Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Zoek.exe v5.0.0.1 Updated 27-09-2015
- Tool run by Jean-Michel Crapaud on 11/03/2017 at 16:38:21.96.
- Microsoft Windows 10 Home 10.0.14393 x64
- Running in: Normal Mode No Internet Access Detected
- Launched: C:\Users\Bernard\Desktop\zoek\zoek.exe [Scan all users] [Script inserted]
- ==== System Restore Info ======================
- 11/03/2017 16:39:02 Zoek.exe System Restore Point Created Successfully.
- ==== Empty Folders Check ======================
- C:\PROGRA~2\MK deleted successfully
- C:\PROGRA~3\ALM deleted successfully
- C:\PROGRA~3\Comms deleted successfully
- C:\PROGRA~3\SoftwareDistribution deleted successfully
- C:\Users\Administrateur\AppData\LocalLow deleted successfully
- C:\Users\Administrateur\AppData\Local\ActiveSync deleted successfully
- C:\Users\Bernard\AppData\Local\ActiveSync deleted successfully
- C:\Users\Bernard\AppData\Local\Ahghtshonge deleted successfully
- C:\Users\Bernard\AppData\Local\Black_Tree_Gaming deleted successfully
- C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\CrashDumps deleted successfully
- C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\NetworkTiles deleted successfully
- ==== Deleting CLSID Registry Keys ======================
- ==== Deleting CLSID Registry Values ======================
- ==== Deleting Services ======================
- ==== Batch Command(s) Run By Tool======================
- ==== Deleting Files \ Folders ======================
- C:\PROGRA~2\MK not found
- C:\Users\Bernard\AppData\Roaming\Amanote deleted
- C:\Users\Bernard\AppData\Roaming\discord deleted
- C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
- C:\PROGRA~3\ProductData deleted
- C:\PROGRA~3\Package Cache deleted
- C:\Users\Bernard\AppData\Local\BitLord deleted
- C:\Users\Bernard\AppData\Local\Wondershare deleted
- C:\windows\SysNative\GroupPolicy\Adm deleted
- C:\windows\SysNative\GroupPolicy\Machine deleted
- C:\windows\SysNative\GroupPolicy\User deleted
- C:\windows\SysNative\GroupPolicy\gpt.ini deleted
- C:\Users\Bernard\Documents\BitLord deleted
- "C:\WINDOWS\Installer\3e9c708.msi" deleted
- "C:\Users\Bernard\AppData\Local\{85ADDFBA-5926-4321-BEE0-E15D55160A9B}" deleted
- "C:\Users\Bernard\AppData\Roaming\WinSnare\WinSnare.dll" deleted
- "C:\Users\Bernard\AppData\Roaming\WinSnare" not deleted
- ==== Firefox Start and Search pages ======================
- ProfilePath: C:\Users\Bernard\AppData\Roaming\Mozilla\Firefox\Profiles\qarxcnrs.default-1489000847466
- user_pref("browser.startup.homepage", "about:home");
- ==== Firefox Extensions ======================
- ProfilePath: C:\Users\Bernard\AppData\Roaming\Mozilla\Firefox\Profiles\qarxcnrs.default-1489000847466
- - Undetermined - %ProfilePath%\extensions\uBlock0@raymondhill.net.xpi
- - iMacros for Firefox - %ProfilePath%\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}.xpi
- AppDir: C:\Program Files (x86)\Mozilla Firefox
- - Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
- ==== Firefox Plugins ======================
- Profilepath: C:\Users\Bernard\AppData\Roaming\Mozilla\Firefox\Profiles\qarxcnrs.default-1489000847466
- 86BD236BE6DA240730EFD2C8026E5B16 - C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll - Shockwave Flash
- CAF78E18A9E1380A0A38065B3B1210E0 - C:\Users\Bernard\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.4\npVascoCardReaderPlugin.dll - VASCO Card Reader Plugin
- 1CDD28B47D8198F868349BDFBCD1281B - C:\Users\Bernard\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.4\npVascoCardReaderPlugin64.dll - VASCO Card Reader Plugin
- ==== Chromium Look ======================
- ==== Set IE to Default ======================
- Old Values:
- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
- "Default_Page_URL"="http://www.startpageing123.com/?type=hp&ts=1489157213&z=537dcad076e37520938849fgczcbat6g3w0mdo7g0o&from=che0812&uid=HGSTXHTS721010A9E630_JS10006206LPAT06LPATX"
- "Default_Search_URL"="http://www.startpageing123.com/search/?type=ds&ts=1489157213&z=537dcad076e37520938849fgczcbat6g3w0mdo7g0o&from=che0812&uid=HGSTXHTS721010A9E630_JS10006206LPAT06LPATX&q={searchTerms}"
- "Search Page"="http://www.startpageing123.com/search/?type=ds&ts=1489157213&z=537dcad076e37520938849fgczcbat6g3w0mdo7g0o&from=che0812&uid=HGSTXHTS721010A9E630_JS10006206LPAT06LPATX&q={searchTerms}"
- "Start Page"="http://www.startpageing123.com/?type=hp&ts=1489157213&z=537dcad076e37520938849fgczcbat6g3w0mdo7g0o&from=che0812&uid=HGSTXHTS721010A9E630_JS10006206LPAT06LPATX"
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
- "Default_Page_URL"="http://www.startpageing123.com/?type=hp&ts=1489157213&z=537dcad076e37520938849fgczcbat6g3w0mdo7g0o&from=che0812&uid=HGSTXHTS721010A9E630_JS10006206LPAT06LPATX"
- "Default_Search_URL"="http://www.startpageing123.com/search/?type=ds&ts=1489157213&z=537dcad076e37520938849fgczcbat6g3w0mdo7g0o&from=che0812&uid=HGSTXHTS721010A9E630_JS10006206LPAT06LPATX&q={searchTerms}"
- "Search Page"="http://www.startpageing123.com/search/?type=ds&ts=1489157213&z=537dcad076e37520938849fgczcbat6g3w0mdo7g0o&from=che0812&uid=HGSTXHTS721010A9E630_JS10006206LPAT06LPATX&q={searchTerms}"
- "Start Page"="http://www.startpageing123.com/?type=hp&ts=1489157213&z=537dcad076e37520938849fgczcbat6g3w0mdo7g0o&from=che0812&uid=HGSTXHTS721010A9E630_JS10006206LPAT06LPATX"
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
- No DefaultScope Set For HKCU
- New Values:
- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
- "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
- "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
- "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
- "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
- "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
- [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
- "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
- "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
- "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
- "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
- "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
- ==== All HKCU SearchScopes ======================
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
- {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
- {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
- {33BB0A4E-99AF-4226-BDF6-49120163DE86} Unknown Url="Not_Found"
- {67C334C0-408D-4E6D-B5A7-0ADD6AFFA252} Google Url="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}"
- ==== Deleting CLSID Registry Keys ======================
- HKEY_USERS\S-1-5-21-2792659385-62999317-2928674910-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E3605470-291B-44EB-8648-745EE356599A} deleted successfully
- HKEY_USERS\S-1-5-21-2792659385-62999317-2928674910-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully
- HKEY_CLASSES_ROOT\CLSID\{E3605470-291B-44EB-8648-745EE356599A} deleted successfully
- HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{E3605470-291B-44EB-8648-745EE356599A} deleted successfully
- HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully
- ==== Deleting CLSID Registry Values ======================
- ==== Deleting Registry Keys ======================
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1F6D371FD48281B4F9E675DD0CE543AE deleted successfully
- HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F173D6F1-284D-4B18-9F6E-57DDC05E34EA} deleted successfully
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\1F6D371FD48281B4F9E675DD0CE543AE deleted successfully
- ==== Empty IE Cache ======================
- C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
- C:\Users\Administrateur\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
- C:\Users\Bernard\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
- C:\Users\Bernard\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
- C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
- C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
- C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
- C:\Users\Administrateur\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
- C:\Users\Bernard\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
- C:\Users\Bernard\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
- C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
- C:\Users\Default User\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
- C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
- ==== Empty FireFox Cache ======================
- C:\Users\Bernard\AppData\Local\Mozilla\Firefox\Profiles\qarxcnrs.default-1489000847466\cache2 emptied successfully
- ==== Empty Chrome Cache ======================
- C:\Users\Bernard\AppData\Local\Blisk\User Data\Default\Cache emptied successfully
- ==== Empty All Flash Cache ======================
- No Flash Cache Found
- ==== Empty All Java Cache ======================
- Java Cache cleared successfully
- ==== C:\zoek_backup content ======================
- C:\zoek_backup (files=1259 folders=1703 3858404576 bytes)
- ==== Empty Temp Folders ======================
- C:\WINDOWS\Temp will be emptied at reboot
- ==== After Reboot ======================
- ==== Empty Temp Folders ======================
- C:\WINDOWS\Temp successfully emptied
- C:\Users\Bernard\AppData\Local\Temp successfully emptied
- ==== Empty Recycle Bin ======================
- C:\$RECYCLE.BIN successfully emptied
- ==== Deleting Files / Folders ======================
- "C:\Users\Bernard\AppData\Roaming\WinSnare" not found
- ==== EOF on 11/03/2017 at 17:09:35.19 ======================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement