Zoek.exe v5.0.0.1 Updated 19-September-2016 Tool run by Beast on wo 02/11/2016 at 13:36:33,51. Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64 Running in: Safe Mode NETWORK Internet Access Detected Launched: C:\Users\Beast\Desktop\zoek.exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2016-11-02-094903.log 20038 bytes C:\zoek-results2016-11-02-104648.log 21133 bytes ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\windows\SysNative\GroupPolicy\Machine deleted C:\windows\SysNative\GroupPolicy\User deleted C:\windows\SysNative\GroupPolicy\GPT.INI deleted C:\Windows\Syswow64\GroupPolicy\gpt.ini deleted ==== Folders Found ====================== ==== Files Found ====================== ==== Registry Search Results for "bluestacks" ====================== [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BSTHDDRV\0000] "DeviceDesc"="BlueStacks Hypervisor" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BstHdDrv] "DisplayName"="BlueStacks Hypervisor" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_BSTHDDRV\0000] "DeviceDesc"="BlueStacks Hypervisor" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\BstHdDrv] "DisplayName"="BlueStacks Hypervisor" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_BSTHDDRV\0000] "DeviceDesc"="BlueStacks Hypervisor" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BstHdDrv] "DisplayName"="BlueStacks Hypervisor" [HKEY_USERS\S-1-5-21-3473739808-715647190-2127078386-1000\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION] "BlueStacks-SplitInstaller_native.exe&SoftwareCommandLine=&LogoUrl=&SoftwareDescription="=dword:00001f40 ==== Registry Search Results for "bluestacks" ====================== [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BSTHDDRV\0000] "DeviceDesc"="BlueStacks Hypervisor" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BstHdDrv] "DisplayName"="BlueStacks Hypervisor" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_BSTHDDRV\0000] "DeviceDesc"="BlueStacks Hypervisor" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\BstHdDrv] "DisplayName"="BlueStacks Hypervisor" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_BSTHDDRV\0000] "DeviceDesc"="BlueStacks Hypervisor" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BstHdDrv] "DisplayName"="BlueStacks Hypervisor" [HKEY_USERS\S-1-5-21-3473739808-715647190-2127078386-1000\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION] "BlueStacks-SplitInstaller_native.exe&SoftwareCommandLine=&LogoUrl=&SoftwareDescription="=dword:00001f40 ==== Orphaned Tasks deleted from Registry ====================== avast Emergency Update deleted ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\Beast\AppData\Roaming\Mozilla\Firefox\Profiles\6d2ypipm.default user_pref("browser.startup.homepage", "www.google.be"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [07/10/2016 08:15] [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [07/10/2016 08:15] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Beast\AppData\Roaming\Mozilla\Firefox\Profiles\6d2ypipm.default - HTTPS-Everywhere - %ProfilePath%\extensions\https-everywhere-eff@eff.org - Disconnect - %ProfilePath%\extensions\2.0@disconnect.me.xpi - YouTube Control Center - %ProfilePath%\extensions\jid1-CikLKKPVkw6ipw@jetpack.xpi - Undo Closed Tabs Button - %ProfilePath%\extensions\undoclosedtabsbutton@supernova00.biz.xpi - SmoothWheel AMO - %ProfilePath%\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}.xpi - Video DownloadHelper - %ProfilePath%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi ==== Firefox Plugins ====================== ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions eofcbnmajmjmplflapaojjnihcjkigck - No path found[] Web of Trust - Beast\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp Spell Bee - Beast\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfbnahffpakjbdlccohcoglcnafhgnhm SimpleUndoClose - Beast\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhohdghchmjepmigjojkehidlielknj Shield For Chrome - Beast\AppData\Local\Google\Chrome\User Data\Default\Extensions\gceighgadbamgchioaofojlblndjcggh Web Timer - Beast\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggnjbdfgigejghknieofeahaknkjafim Hover Free - Beast\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcmnnggnaofmhflgomfjfbndngdoogkj IE Tab - Beast\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd Social Fixer for Facebook - Beast\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifmhoabcaeehkljcfclfiieohkohdgbb Disconnect - Beast\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo Momentum - Beast\AppData\Local\Google\Chrome\User Data\Default\Extensions\laookkfknpbbblfpciffpaejjkokdgca Currency Converter - Beast\AppData\Local\Google\Chrome\User Data\Default\Extensions\lncdobdbibdgoiohgnflmjajfphcnakg Google Dictionary (by Google) - Beast\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja Save to Pocket - Beast\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj Virtual Keyboard - Beast\AppData\Local\Google\Chrome\User Data\Default\Extensions\pflmllfnnabikmfkkaddkoolinlfninn Chrome Media Router - Beast\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com/" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Beast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Beast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\Beast\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=4 folders=2 41176 bytes) ==== Empty Temp Folders ====================== C:\Users\Beast\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Beast\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on wo 02/11/2016 at 13:44:34,01 ======================