Vkládám LOG-1
Zoek.exe v5.0.0.2 Updated 29-March-2018(online version)
Tool run by xxx on st 11.04.2018 at 15:00:50,78.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\xxx\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1312145065-2419162411-1920721547-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E8F97CD-60B5-456F-A201-73065652D099} deleted successfully
HKEY_USERS\S-1-5-21-1312145065-2419162411-1920721547-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E8F97CD-60B5-456F-A201-73065652D099} deleted successfully
HKEY_USERS\S-1-5-21-1312145065-2419162411-1920721547-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1E1B2879-88FF-11D2-8D96-D7ACAC95951F} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E1B2879-88FF-11D2-8D96-D7ACAC95951F} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-1312145065-2419162411-1920721547-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{79b8e308-95a2-4044-932d-80e833a863cc} deleted successfully
HKEY_USERS\S-1-5-21-1312145065-2419162411-1920721547-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975} deleted successfully
HKEY_USERS\S-1-5-21-1312145065-2419162411-1920721547-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{48A789BF-F6D6-4930-9C8B-77855A63EDE1} deleted successfully
HKEY_USERS\S-1-5-21-1312145065-2419162411-1920721547-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4ba58ed5-2614-4e24-9fe9-7938ebfd00c5} deleted successfully
HKEY_USERS\S-1-5-21-1312145065-2419162411-1920721547-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{0AFFDAEC-04C3-46F2-BA26-62E5B50492BD} deleted successfully
HKEY_USERS\S-1-5-21-1312145065-2419162411-1920721547-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{A66261FC-B82E-4EC7-9F6D-C2F36B871DF0} deleted successfully
HKEY_USERS\S-1-5-21-1312145065-2419162411-1920721547-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{2A836234-186C-41A0-9863-40BECDEDED9F} deleted successfully
HKEY_USERS\S-1-5-21-1312145065-2419162411-1920721547-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{8E8F97CD-60B5-456F-A201-73065652D099} deleted successfully
HKEY_USERS\S-1-5-21-1312145065-2419162411-1920721547-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\{ABDE892B-13A8-4d1b-88E6-365A6E755758} deleted successfully
==== FireFox Fix ======================
Deleted from C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\q47now0d.default\prefs.js:
user_pref("browser.startup.homepage", "
http://mail.ru/cnt/10445?gp=811141");
user_pref("browser.newtab.url", "
https://search.yahoo.com/yhs/web?hspart ... 0211__yaff");
user_pref("browser.search.selectedEngine", "Yahoo®");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", false);
Added to C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\q47now0d.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\xxx\AppData\Roaming\Thunderbird\Profiles\igomfcmj.default\prefs.js:
Added to C:\Users\xxx\AppData\Roaming\Thunderbird\Profiles\igomfcmj.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\q47now0d.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\xxx\AppData\Roaming\Thunderbird\Profiles\igomfcmj.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files\McAfee\SiteAdvisor\e10ssaffplg.xpi" [06.04.2018 08:00]
==== Firefox Extensions ======================
ProfilePath: C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\q47now0d.default
- Undetermined - %ProfilePath%\extensions\
sko-extension@firma.seznam.cz
- Undetermined - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
- Undetermined - %ProfilePath%\extensions\
homepage@mail.ru.xpi
- Undetermined - %ProfilePath%\extensions\
search@mail.ru.xpi
- Undetermined - %ProfilePath%\extensions\{a38384b3-2d1d-4f36-bc22-0f7ae402bcd7}.xpi
ProfilePath: C:\Users\xxx\AppData\Roaming\Thunderbird\Profiles\igomfcmj.default
- Lightning - %ProfilePath%\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}
ExtDir: C:\Users\xxx\AppData\Roaming\Mozilla\Extensions
- Speed Analysis 3 - %ExtDir%\
speedanalysis03@SpeedAnalysis.com
- Zula Games - %ExtDir%\
zulagames@ZulaGames.com
==== Firefox Plugins ======================
Profilepath: C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\q47now0d.default
40FEA91F23AE9F917EAC9753D62EA84A - C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll - Adobe Acrobat
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://www.msn.com/"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{FFEBBF0A-C22C-4172-89FF-45215A135AC7}"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="
http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
==== All HKLM and HKCU SearchScopes ======================
HKLM\SearchScopes "DefaultScope"="{E9410C70-B6AE-41FF-AB71-32F4B279EA5F}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} -
http://www.google.com/search?q={searchT ... urceid=ie7
HKLM\SearchScopes\{AB64792C-7080-4E2F-B393-F93B84B21279} -
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} -
http://www.bing.com/search?q={searchTer ... DF&pc=MSE1
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} -
http://www.bing.com/search?q={searchTer ... ORM=IE8SRC
HKCU\SearchScopes\{1E0FD48B-EFE4-43BA-BF80-F5B095D663F0} -
http://www.novinky.cz/hledej?w={searchT ... arch_12454
HKCU\SearchScopes\{248293C5-D907-424A-9870-A1AAF3F616EB} -
http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
HKCU\SearchScopes\{4BE9030C-21B6-4FB7-8603-0B38F6378265} -
http://encyklopedie.seznam.cz/search?q= ... arch_12454
HKCU\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} -
http://www.google.com/search?q={searchT ... urceid=ie7
HKCU\SearchScopes\{80D05449-5284-4329-B3EA-E9FF6F1A8BB9} -
http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
HKCU\SearchScopes\{833B923C-B732-48B4-B1AB-45CCDBEFAE73} -
http://www.mapy.cz/?query={searchTerms} ... arch_12454
HKCU\SearchScopes\{A05F2DB9-D67B-497E-84BE-4D4606BF8B80} -
http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
HKCU\SearchScopes\{AB64792C-7080-4E2F-B393-F93B84B21279} -
http://www.bing.com/search?FORM=SK2MDF& ... -SearchBox
HKCU\SearchScopes\{C0C3A6C6-03BC-4195-8FCB-AEA091301353} -
https://search.yahoo.com/yhs/search?hsp ... earchTerms}
HKCU\SearchScopes\{C806F8DF-3DBD-4CEE-8ECF-3495F90F8D80} -
http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
HKCU\SearchScopes\{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} -
http://www.bing.com/search?q={searchTer ... DF&pc=MSE1
HKCU\SearchScopes\{EC6803C7-F273-45D1-85DD-94EC75F94B5D} -
http://www.firmy.cz/?q={searchTerms}&so ... arch_12454
HKCU\SearchScopes\{FBC48B2A-67DF-4B3F-8E76-EDA7F8EDDF53} -
http://search.seznam.cz/?q={searchTerms ... arch_12454
HKCU\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7} -
http://go.mail.ru/distib/ep/?q={searchT ... &gp=811142
==== Reset Google Chrome ======================
C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Profile 1\Secure Preferences was reset successfully
C:\Users\xxx\Appdata\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\xxx\Appdata\Roaming\Opera Software\Opera Stable\Preferences.backup was reset successfully
C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Web Data copy was reset successfully
C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully
C:\Users\xxx\Appdata\Roaming\Opera Software\Opera Stable\Web Data was reset successfully
C:\Users\xxx\Appdata\Roaming\Opera Software\Opera Stable\Web Data-journal was reset successfully
==== Empty IE Cache ======================
C:\Users\xxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\xxx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Cache found
==== Empty Chrome Cache ======================
C:\Users\xxx\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=0 folders=0 0 bytes)
==== Empty Temp Folders ======================
C:\Users\Administrator\AppData\Local\temp emptied successfully
C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\DefaultAppPool\AppData\Local\temp emptied successfully
C:\Users\Guest\AppData\Local\temp emptied successfully
C:\Users\xxx\AppData\Local\temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\xxx\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on st 11.04.2018 at 15:11:05,18 ======================