Zoek.exe v5.0.0.0 Updated 20-December-2014
Tool run by Josiah on Sat 12/20/2014 at 5:30:02.53.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Josiah\Downloads\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
12/20/2014 5:33:16 AM Zoek.exe System Restore Point Created Succesfully.
==== Empty Folders Check ======================
C:\PROGRA~2\Adblocker deleted successfully
C:\PROGRA~2\AGEIA Technologies deleted successfully
C:\PROGRA~2\Bethesda Softworks deleted successfully
C:\PROGRA~2\Malwarebytes' Anti-Malware deleted successfully
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\Origin Games deleted successfully
C:\PROGRA~3\Oracle deleted successfully
C:\PROGRA~3\Telestream deleted successfully
C:\PROGRA~3\Trusted Publisher deleted successfully
C:\Users\Josiah\AppData\Roaming\Malwarebytes deleted successfully
C:\Users\Josiah\AppData\Roaming\Publish Providers deleted successfully
C:\Users\Josiah\AppData\Roaming\TP deleted successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1814413989-3838121923-1208062030-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{e9e8eb35-ff77-455d-b677-91e5e4fc06c2} deleted successfully
HKEY_USERS\S-1-5-21-1814413989-3838121923-1208062030-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{e9e8eb35-ff77-455d-b677-91e5e4fc06c2} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{e9e8eb35-ff77-455d-b677-91e5e4fc06c2} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
ProfilePath: C:\Users\Josiah\AppData\Roaming\Mozilla\Firefox\Profiles\9ezrh32r.default
---- Lines easylife removed from prefs.js ----
user_pref("extensions.SpZPbUF6S4afeQ43.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||
user_pref("extensions.VJTEzJPzcw19Nzms.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||
---- Lines extensions.B5q1SmaxSljPyBaq removed from prefs.js ----
user_pref("extensions.B5q1SmaxSljPyBaq.epoch", "1");
user_pref("extensions.B5q1SmaxSljPyBaq.scode", "void(0);");
user_pref("extensions.B5q1SmaxSljPyBaq.url", "
http://newtonial.in/sync/?q=C6qUojY...MAyVUojw8rdn7rHC6qTa7pdsGqHw7qHCFtNtVh7n0rjnF
---- Lines extensions.E6ek removed from prefs.js ----
user_pref("extensions.E6ek.epoch", "1412730328");
user_pref("extensions.E6ek.url", "
http://toolkitfree.us/sync2/?q=hfZ9...heDUojw9rdYGqTaEqjwEqGhIC7n0rjnFrda6rdwEpdnEt
---- Lines extensions.SpZPbUF6S4afeQ43 removed from prefs.js ----
user_pref("extensions.SpZPbUF6S4afeQ43.epoch", "1412730327");
user_pref("extensions.SpZPbUF6S4afeQ43.url", "
http://veterant.info/sync2/?q=hfZ9o...NmGWj8lkGhGheDUojw9rjaEqHaEqjg9qGhIC7n0rjnFrd
---- Lines extensions.VJTEzJPzcw19Nzms removed from prefs.js ----
user_pref("extensions.VJTEzJPzcw19Nzms.epoch", "1412730328");
user_pref("extensions.VJTEzJPzcw19Nzms.url", "
http://veterances.info/sync2/?q=hfZ...8BNmGWj8lkGhGheDUojw9rjaEqHaErdC9rShIC7n0rjnF
---- Lines extensions.W167Twj removed from prefs.js ----
user_pref("extensions.W167Twj.epoch", "1412730327");
user_pref("extensions.W167Twj.url", "
http://veterances.com/sync2/?q=hfZ9...NtVh7n0rjnEpdw4rjCHqjrHtMFHhd9FqdwErdCErja5qd
---- Lines extensions.iTWNpoRpV removed from prefs.js ----
user_pref("extensions.iTWNpoRpV.epoch", "1412730328");
user_pref("extensions.iTWNpoRpV.url", "
http://jpi-syncer.info/sync2/?q=hfZ...8lkGhGheDUojw9rdYFpjw6rHkFqGhIC7n0rjnFrda6rdw
---- FireFox user.js and prefs.js backups ----
user_20141220_0606_.backup
prefs_20141220_0606_.backup
==== Batch Command(s) Run By Tool======================
==== Deleting Files \ Folders ======================
C:\Users\Josiah\AppData\Roaming\ProtectDISC deleted
C:\ProgramData\EnjeoyCCouopon deleted
C:\ProgramData\FunDealss deleted
C:\ProgramData\NewSSaver deleted
C:\Users\Josiah\AppData\LocalLow\{AFAA812D-59BF-F66A-58E4-CB6B0DACD9B0} deleted
C:\Users\Josiah\AppData\LocalLow\{F308B536-4389-52E7-3B85-F8C4E330B505} deleted
C:\Users\Josiah\AppData\Local\Packages\windows_ie_ac_001\AC\{AFAA812D-59BF-F66A-58E4-CB6B0DACD9B0} deleted
C:\Users\Josiah\AppData\Local\Packages\windows_ie_ac_001\AC\{F308B536-4389-52E7-3B85-F8C4E330B505} deleted
C:\PROGRA~3\272f24668dac0699 deleted
C:\PROGRA~3\prIIcecchoPP deleted
C:\PROGRA~2\prIIcecchoPP deleted
C:\PROGRA~2\ProtectDisc Driver Installer deleted
C:\Users\Josiah\AppData\Roaming\appdataFr2.bin deleted
C:\Users\Josiah\AppData\Roaming\MAGIX deleted
C:\PROGRA~3\HirezPipeError.txt deleted
C:\PROGRA~3\NuewSuAver deleted
C:\PROGRA~3\MAGIX deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Josiah\AppData\LocalLow\{69C5679C-0A61-AB45-0E1F-34582F720632} deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\Windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Windows\Syswow64\shoCF31.tmp deleted
C:\Windows\SysWow64\AI_RecycleBin deleted
C:\Users\Josiah\AppData\Roaming\Mozilla\Firefox\Profiles\9ezrh32r.default\extensions\staged deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"
ytfmdownloader@gmail.com"="C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\
ytfmdownloader@gmail.com" [02/10/2013 07:47 PM]
==== Firefox Extensions ======================
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Josiah\AppData\Roaming\Mozilla\Firefox\Profiles\9ezrh32r.default
3CD19649B2C3023D65E67C056457A2BC - C:\Users\Josiah\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin
==== Fake Chromium Profiles Check ======================
Fake profile C:\Users\Administrator\AppData\Local\Torch deleted
Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome deleted
Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome SxS deleted
Fake profile C:\Users\Administrator\AppData\Local\Comodo\Dragon deleted
Fake profile C:\Users\Administrator\AppData\Local\Chromatic Browser deleted
Fake profile C:\Users\Guest\AppData\Local\Torch deleted
Fake profile C:\Users\Guest\AppData\Local\Google\Chrome deleted
Fake profile C:\Users\Guest\AppData\Local\Google\Chrome SxS deleted
Fake profile C:\Users\Guest\AppData\Local\Comodo\Dragon deleted
Fake profile C:\Users\Guest\AppData\Local\Chromatic Browser deleted
Fake profile C:\Users\HomeGroupUser$\AppData\Local\Torch deleted
Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome deleted
Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS deleted
Fake profile C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon deleted
Fake profile C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser deleted
Fake profile C:\Users\Josiah\AppData\Local\Torch deleted
Fake profile C:\Users\Josiah\AppData\Local\Google\Chrome SxS deleted
Fake profile C:\Users\Josiah\AppData\Local\Comodo\Dragon deleted
Fake profile C:\Users\Josiah\AppData\Local\Chromatic Browser deleted
Fake profile C:\Users\UpdatusUser\AppData\Local\Torch deleted
Fake profile C:\Users\UpdatusUser\AppData\Local\Google\Chrome deleted
Fake profile C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS deleted
Fake profile C:\Users\UpdatusUser\AppData\Local\Comodo\Dragon deleted
Fake profile C:\Users\UpdatusUser\AppData\Local\Chromatic Browser deleted
==== Chromium Look ======================
Google Chrome Version: 36.0.1985.143 (Could not determine latest Stable Version)
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
bpegkgagfojjbcpkihigfmkojdmmimdf - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx[02/01/2013 10:31 AM]
ehgldbbpchgpcfagfpfjgoomddhccfgh - C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx[02/01/2013 10:31 AM]
jbolfgndggfhhpbnkgnpjkfhinclbigj - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx[09/11/2012 09:45 AM]
Google Voice Search Hotword (Beta) - Josiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn
Twitch Giveaways - Josiah\AppData\Local\Google\Chrome\User Data\Default\Extensions\poohjpljfecljomfhhimjhddddlidhdd
==== Chromium Startpages ======================
C:\Users\Josiah\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "
http://www.google.com/",
==== Chromium Fix ======================
C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx deleted successfully
C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx deleted successfully
C:\Users\Josiah\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_
www.superfish.com_0.localstorage deleted successfully
C:\Users\Josiah\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_
www.superfish.com_0.localstorage-journal deleted successfully
C:\Users\Josiah\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_
www.superfish.com_0.localstorage deleted successfully
C:\Users\Josiah\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_
www.superfish.com_0.localstorage-journal deleted successfully
C:\Users\Josiah\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage deleted successfully
C:\Users\Josiah\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully
C:\Users\Josiah\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_
www.ask.com_0.localstorage deleted successfully
C:\Users\Josiah\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_
www.ask.com_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="
http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2DF3E224-05CD-4113-AA7A-86F2F6607B46} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{478472F9-9E09-492A-BDAB-42EE595EF1AD} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{64A4ABCA-CF3D-C548-2DC4-72A55DC5882A} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6A08B379-76FB-B4CF-0C70-CAFCD3635A77} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C637A71C-A4B2-4B47-1B2A-1042A8D525A3} deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Josiah\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Josiah\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Josiah\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Josiah\AppData\Local\Mozilla\Firefox\Profiles\9ezrh32r.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Josiah\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=126 folders=179 40384248 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\DefaultAppPool\AppData\Local\Temp emptied successfully
C:\Users\Josiah\AppData\Local\Temp will be emptied at reboot
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Josiah\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found
==== EOF on Sat 12/20/2014 at 6:26:45.49 ======================