....update!! It won't let me upload my zoek file - it says the file is empty ... so I will copy the text below:
Zoek.exe v5.0.0.0 Updated 23-04-2015
Tool run by Chris aka CGP on 27/04/2015 at 18:24:59.22.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Chris aka CGP\Downloads\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
27/04/2015 18:29:05 Zoek.exe System Restore Point Created Successfully.
==== Empty Folders Check ======================
C:\PROGRA~2\Deal Keeper deleted successfully
C:\PROGRA~2\Optimizer Pro deleted successfully
C:\PROGRA~2\COMMON~1\Symantec Shared deleted successfully
C:\Program Files\PPS deleted successfully
C:\PROGRA~3\374311380 deleted successfully
C:\Users\Chris aka CGP\AppData\Local\CUSTPDF Writer deleted successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-3297290139-40113303-3829120269-1002\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} deleted successfully
HKEY_USERS\S-1-5-21-3297290139-40113303-3829120269-1002\Software\Microsoft\Internet Explorer\SearchScopes\{8E805679-AD2E-430A-8FEF-7F95E3F96A85} deleted successfully
HKEY_USERS\S-1-5-21-3297290139-40113303-3829120269-1002\Software\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{8E805679-AD2E-430A-8FEF-7F95E3F96A85} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8E805679-AD2E-430A-8FEF-7F95E3F96A85} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util Deal Keeper deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util Deal Keeper deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update Deal Keeper deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update Deal Keeper deleted successfully
==== FireFox Fix ======================
ProfilePath: C:\Users\CHRISA~1\AppData\Roaming\Mozilla\Firefox\Profiles\43n2w39d.default
---- Lines Deal Keeper removed from prefs.js ----
user_pref("extensions.Deal Keeper.asul", "1406714659876");
user_pref("extensions.Deal Keeper.aul", "1406714658645");
user_pref("extensions.Deal Keeper.irl", true);
user_pref("extensions.Deal Keeper.is", "isgiwhGB");
user_pref("extensions.Deal Keeper.ug", "C1667FAD-3EA6-4641-90B1-D8A79C2C3CEE");
---- Lines astrmndant removed from prefs.js ----
user_pref("extensions.astrmndant.aflt", "ast_dsites05_14_31_ff");
user_pref("extensions.astrmndant.cd", "2XzuyEtN2Y1L1Qzu0AyEyD0DtAyCyCyCtD0DtB0ByEyCzzyBtN0D0Tzu0SzyyEtCtN1L2XzutBtFtBtCtFtCzztFtAtN1L1CzutCyEtBzytDyD1
user_pref("extensions.astrmndant.cr", "1157670745");
user_pref("extensions.astrmndant.instlRef", "142905_b");
---- Lines astrmndant removed from user.js ----
user_pref("extensions.astrmndant.aflt", "ast_dsites05_14_31_ff");
user_pref("extensions.astrmndant.instlRef", "142905_b");
user_pref("extensions.astrmndant.cr", "1157670745");
user_pref("extensions.astrmndant.cd", "2XzuyEtN2Y1L1Qzu0AyEyD0DtAyCyCyCtD0DtB0ByEyCzzyBtN0D0Tzu0SzyyEtCtN1L2XzutBtFtBtCtFtCzztFtAtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyC0BtCtByBtDtCyCtG0AtA0B0FtGtA0E0C0FtGtBzz0DtCtGtD0BtC0BzzyEyByEyCyC0F0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCzzyD0Bzz0CyE0AtG0FtD0E0FtG0FtD0E0EtGyDyE0C0DtGtCyD0ByBzy0FyCzz0B0CtC0F2Q");
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 3);
---- FireFox user.js and prefs.js backups ----
user_042015_1956_.backup
prefs_042015_1956_.backup
==== Batch Command(s) Run By Tool======================
==== Deleting Files \ Folders ======================
C:\PROGRA~2\Deal Keeper not found
C:\PROGRA~2\Optimizer Pro not found
C:\windows\SysNative\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4} deleted
C:\Users\Chris aka CGP\.android deleted
C:\PROGRA~2\Connected Music powered by Universal Music Group deleted
C:\Users\Chris aka CGP\AppData\Roaming\DigitalSites deleted
C:\Users\Chris aka CGP\AppData\Local\Z@!-49ff9772-1a66-451c-9107-b6857196151f.tmp deleted
C:\Users\Chris aka CGP\AppData\Local\Z@S!-970d47e1-f2ab-44d1-902c-8234e1712954.tmp deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\windows\SysNative\tasks\Digital Sites deleted
C:\WINDOWS\tasks\Digital Sites.job deleted
"C:\WINDOWS\Installer\131add.msi" deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"
wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [14/04/2015 18:24]
==== Firefox Extensions ======================
ProfilePath: C:\Users\CHRISA~1\AppData\Roaming\Mozilla\Firefox\Profiles\43n2w39d.default
- LastPass - C:\Users\Chris aka CGP\AppData\Roaming\Mozilla\Firefox\Profiles\43n2w39d.default\extensions\
support@lastpass.com
- Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- LastPass - %ProfilePath%\extensions\
support@lastpass.com
- TrackIf Web amp; Price Tracker - %ProfilePath%\extensions\
jid0-qmqbjs9nLPAkgUQrbxaBmO3a6gY@jetpack.xpi
- KidStart Savings Prompt - %ProfilePath%\extensions\
KidStart@KidStart.xpi
- Google Image Search - %ProfilePath%\extensions\{73007fef-a6e0-47d3-b4e7-dfc116ed6f65}.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Chris aka CGP\AppData\Roaming\Mozilla\Firefox\Profiles\43n2w39d.default
3D3CAF586124C4E8102764C8B3063BB6 - C:\windows\SysWOW64\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director
DFC9460CC37E5C414DC4680B10C19E7A - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll - Shockwave Flash
9AE02005247DA91AB1743F5208DBEF76 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll - Shockwave Flash
E3D40D344C196E66D4346CCECED7AC1C - C:\Users\Chris aka CGP\AppData\Roaming\HewlettPackard\HPDetect\1.0.0.0\npHPDetect.dll - HPDetect
E3B4EA121F7BDEB0F6366E2BA9608CB5 - C:\Users\Chris aka CGP\AppData\Local\Citrix\Plugins\104\npappdetector.dll - Citrix Online Web Deployment Plugin 1.0.0.104
==== Chromium Look ======================
Google Chrome Version: 42.0.2311.90 (Latest Stable version: 42.0.2311.90) [z-db]
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[19/03/2015 20:22]
HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
lmjegmlicamnimmfhcmpkclmigmmcbeh - No path found[]
TrackIf Web & Price Tracker - Chris aka CGP\AppData\Local\Google\Chrome\User Data\Default\Extensions\donafdekbhlobcfppmfkpjmeijnnoacd
Bookmark Manager - Chris aka CGP\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik
LastPass - Chris aka CGP\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd
DS Amazon Quick View - Chris aka CGP\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkompbllimaoekaogchhkmkdogpkhojg
Chrome Hotword Shared Module - Chris aka CGP\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg
==== Chromium Startpages ======================
C:\Users\Chris aka CGP\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "
http://trackif.com/",
"startup_urls": [ "
http://astromenda.com/?f=7&a=ast_ds...GtCyD0ByBzy0FyCzz0B0CtC0F2Q&cr=1157670745&ir=" ]
==== Chromium Fix ======================
C:\Users\Chris aka CGP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage deleted successfully
C:\Users\Chris aka CGP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully
C:\Users\Chris aka CGP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.winner.co.uk_0.localstorage deleted successfully
C:\Users\Chris aka CGP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.winner.co.uk_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://g.uk.msn.com/HPNOT13/2"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://g.uk.msn.com/HPNOT13/2"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="
http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Unknown Url="Not_Found"
{2E00D31D-D171-423D-836D-1A4D7EA7F1A9} Bing Url="
http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS"
{D944BB61-2E34-4DBF-A683-47E505C587DC} eBay Url="
http://rover.ebay.com/rover/1/710-29550-11896-25/4"
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-3297290139-40113303-3829120269-1002\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2C0D8C2E79C150C439A9B5310AEF56C5 deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E2C8D0C2-1C97-4C05-939A-5B13A0FE655C} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\2C0D8C2E79C150C439A9B5310AEF56C5 deleted successfully
==== Empty IE Cache ======================
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Chris aka CGP\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Chris aka CGP\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Chris aka CGP\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Chris aka CGP\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Chris aka CGP\AppData\Local\Mozilla\Firefox\Profiles\43n2w39d.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Chris aka CGP\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=64 folders=45 15332311 bytes)
==== Empty Temp Folders ======================
C:\Users\Chris aka CGP\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\WINDOWS\Temp successfully emptied
C:\Users\CHRISA~1\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on 27/04/2015 at 20:34:50.20 ======================