Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Cam on 01/02/2016 at 1:00:29.32.
Microsoft Windows 8 Pro 6.2.9200 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Cam\Downloads\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
01/02/2016 01:08:27 Zoek.exe System Restore Point Created Successfully.
==== Empty Folders Check ======================
C:\PROGRA~2\AGEIA Technologies deleted successfully
C:\PROGRA~2\DivX deleted successfully
C:\PROGRA~3\Avg deleted successfully
C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) deleted successfully
C:\Users\Cam\AppData\Roaming\sparta111 deleted successfully
C:\Users\Cam\AppData\Roaming\uTorrent deleted successfully
C:\Users\Cam\AppData\Local\Skype deleted successfully
C:\Users\Cam\AppData\Local\Sparta deleted successfully
C:\Users\Cam\AppData\Local\WarThunder deleted successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\PeerDistPub deleted successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\PeerDistRepub deleted successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-626473118-3010605479-898090307-1001\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully
==== Deleting Services ======================
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vToolbarUpdater14.2.0 deleted successfully
==== Batch Command(s) Run By Tool======================
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
==== Deleting Files \ Folders ======================
C:\PROGRA~2\AGEIA Technologies not found
C:\PROGRA~2\DivX not found
C:\PROGRA~3\Malwarebytes' Anti-Malware (portable) not found
C:\PROGRA~2\Flyordie Plugin deleted
C:\windows\SysNative\Tasks\Bidaily Synchronize Task[973b] deleted
C:\Windows\tasks\Bidaily Synchronize Task[973b].job deleted
C:\PROGRA~3\{7c12c1dc-c294-1c6e-7c12-2c1dcc290773} deleted
C:\PROGRA~3\5767796595995162811 deleted
C:\PROGRA~3\DivX deleted
C:\PROGRA~2\SearchProtect deleted
C:\PROGRA~2\File Scout deleted
C:\PROGRA~2\COMMON~1\AVG Secure Search deleted
C:\prefs.js deleted
C:\Users\Cam\AppData\Roaming\RHEng deleted
C:\Users\Cam\AppData\Roaming\Systweak deleted
C:\Users\Cam\AppData\Roaming\OpenCandy deleted
C:\PROGRA~3\AVG Security Toolbar deleted
C:\PROGRA~3\IBUpdaterService deleted
C:\PROGRA~3\AVG SafeGuard toolbar deleted
C:\PROGRA~3\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Cam\AppData\Local\SearchProtect deleted
C:\Users\Cam\AppData\Local\Unity deleted
C:\Users\Cam\AppData\Local\AVG Secure Search deleted
C:\Users\Cam\AppData\Local\Systweak deleted
C:\Users\Cam\AppData\Local\AVG SafeGuard toolbar deleted
C:\Users\Cam\AppData\Local\adawarebp deleted
C:\Users\Cam\AppData\Local\AVG Nation toolbar deleted
C:\Users\Cam\AppData\Local\CrashRpt deleted
C:\Users\Cam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sparta deleted
C:\Windows\SysNative\roboot64.exe deleted
C:\Users\Cam\AppData\LocalLow\AVG SafeGuard toolbar deleted
C:\Users\Cam\AppData\LocalLow\Unity deleted
C:\END deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\Windows\Syswow64\SearchProtect deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"avg@toolbar"="C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\14.2.0.1" []
==== Chromium Look ======================
Google Chrome Version: 46.0.2490.86
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
lfffjahnfbocnaooecgijfnbpcfekoik - C:\ProgramData\adawaretb\shortcuts\chrome\adawaretb.crx[]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[08/01/2016 10:47]
ndibdjnfmopecpmkdieinmbadjfpblof - C:\ProgramData\AVG SafeGuard toolbar\ChromeExt\14.2.0.1\avg.crx[]
Ask Toolbar - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aaaalipaokhkccgmgkdglfinfnfhflko
Comodo Drag&Drop Service - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aneodkojaglhnkkdbbdnmmmgimlcaogo
Comodo Web Inspector - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn
PrivDog - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja
Comodo Media Downloader - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\dihmnpngfonlhjmgkflpnibiaaliendo
Absolute Radio Live Scores - Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kgmkadilkeimcolingoooifhoknpkifi
AVG SafeGuard toolbar - Cam\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
==== Chromium Startpages ======================
C:\Users\Cam\AppData\Local\Comodo\Dragon\User Data\Default\Preferences
"homepage": "
Search",
==== Chromium Fix ======================
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_cdncache-a.akamaihd.net_0.localstorage deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_cdncache-a.akamaihd.net_0.localstorage-journal deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_en.savefrom.net_0.localstorage deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_en.savefrom.net_0.localstorage-journal deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_admtpmp123.adk2x.com_0.localstorage deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_admtpmp123.adk2x.com_0.localstorage-journal deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.donation-tools.org_0.localstorage deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.donation-tools.org_0.localstorage-journal deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_
www.tunefind.com_0.localstorage deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_
www.tunefind.com_0.localstorage-journal deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ads1.msads.net_0.localstorage deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ads1.msads.net_0.localstorage-journal deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage-journal deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage-journal deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage-journal deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_pstatic.bestpriceninja.com_0.localstorage deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_pstatic.bestpriceninja.com_0.localstorage-journal deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage-journal deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_career-services.careerone.com.au_0.localstorage deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_career-services.careerone.com.au_0.localstorage-journal deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_roysautoservices.com_0.localstorage deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_roysautoservices.com_0.localstorage-journal deleted successfully
C:\Users\Cam\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully
C:\Users\Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aaaalipaokhkccgmgkdglfinfnfhflko deleted successfully
C:\Users\Cam\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_aaaalipaokhkccgmgkdglfinfnfhflko_0.localstorage deleted successfully
C:\Users\Cam\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_aaaalipaokhkccgmgkdglfinfnfhflko_0.localstorage-journal deleted successfully
C:\Users\Cam\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kgmkadilkeimcolingoooifhoknpkifi deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos"
"Search Page"="
http://isearch.omiga-plus.com/web/?...0DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}"
"Default_Page_URL"="
Google"
"Default_Search_URL"="
http://isearch.omiga-plus.com/web/?...0DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="
http://isearch.omiga-plus.com/web/?...0DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}"
"Default_Page_URL"="
Google"
"Search Page"="
http://isearch.omiga-plus.com/web/?...0DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="
http://isearch.omiga-plus.com/web/?...0DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}"
"Default_Page_URL"="
Google"
"Search Page"="
http://isearch.omiga-plus.com/web/?...0DLE630_MSK5215H01Z0PG01Z0PGX&q={searchTerms}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="
Bing"
"Default_Search_URL"="
Bing"
"Default_Page_URL"="
MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos"
"Start Page"="
MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="
Bing"
"Search Page"="
Bing"
"Default_Page_URL"="
MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="
Bing"
"Search Page"="
Bing"
"Default_Page_URL"="
MSN.com - Hotmail, Outlook, Skype, Bing, Latest News, Photos & Videos"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"
==== All HKLM and HKCU SearchScopes ======================
HKLM\SearchScopes "DefaultScope"="{33BB0A4E-99AF-4226-BDF6-49120163DE86}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
{searchTerms} - Bing
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{BB82DE59-BC4C-4172-9AC4-73315F71CFFE}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
{searchTerms} - Bing
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} -
{searchTerms} - Google Search
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
{searchTerms} - Bing
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\lfffjahnfbocnaooecgijfnbpcfekoik deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{06B99631-BFA2-3B7A-F58B-D067C2BA59B7} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar deleted successfully
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\UnityWebPlayer deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\omiga-plus uninstall deleted successfully
==== Empty IE Cache ======================