Zoek.exe Version 4.0.0.5 Updated 05-November-2013 Tool run by Evita on vr 08/11/2013 at 20:39:59,63. Microsoft Windows 7 Home Premium 6.1.7600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Evita\Desktop\zoek\zoek.com [Script inserted] ==== System Restore Info ====================== 8/11/2013 20:41:55 Zoek.exe System Restore Point Created Succesfully. ==== Torpig Check ====================== HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\FileSystem {217FC9C0-3AEA-1069-A2DB-08002B30309D} %SystemRoot%\system32\shell32.dll HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing {40dd6e20-7c17-11ce-a804-00aa003ca9f6} %SystemRoot%\system32\ntshrui.dll ==== Empty Folders Check ====================== C:\Program Files\Symantec deleted successfully C:\ProgramData\Big Fish Games deleted successfully C:\Users\Evita\AppData\Roaming\Windows Live Writer deleted successfully C:\Users\Evita\AppData\Local\Cyberlink deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AC19BD04-5E24-41DD-A915-1F783BA0BB9F} deleted successfully HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dealplylivem deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\dealplylivem deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dealplylive deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\dealplylive deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CltMngSvc deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\CltMngSvc deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\application updater deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\application updater deleted successfully ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command] @="C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command] @="C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe" ==== Deleting Files \ Folders ====================== C:\PROGRA~2\Application Updater deleted C:\PROGRA~2\DVDVideoSoftTB deleted C:\PROGRA~2\COMMON~1\DVDVideoSoft\TB deleted C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted C:\PROGRA~2\uTorrentBar_NL deleted C:\PROGRA~2\SearchProtect deleted C:\PROGRA~2\Ss-Helper deleted C:\PROGRA~2\YouTube Downloader Toolbar deleted C:\PROGRA~2\DealPly deleted C:\PROGRA~2\DealPlyLive deleted C:\PROGRA~2\ElectroLyrics-16 deleted C:\PROGRA~2\WebSearch deleted C:\PROGRA~2\WhiteSmoke_New_V6 deleted C:\PROGRA~2\Conduit deleted C:\PROGRA~2\SearchNewTab deleted C:\PROGRA~2\COMMON~1\Spigot deleted C:\extensions deleted C:\SearchProtect deleted C:\Users\Evita\AppData\Roaming\DVDVideoSoftIEHelpers deleted C:\Users\Evita\AppData\Roaming\Dealply deleted C:\Users\Evita\AppData\Roaming\OpenCandy deleted C:\ProgramData\5709056.pad deleted C:\ProgramData\5709056.reg deleted C:\ProgramData\5709056.bat deleted C:\ProgramData\Conduit deleted C:\ProgramData\Registry Helper deleted C:\ProgramData\boost_interprocess deleted C:\ProgramData\DealPlyLive deleted C:\ProgramData\SearchNewTab deleted C:\ProgramData\InstallMate deleted C:\ProgramData\WinterSoft deleted C:\ProgramData\Trymedia deleted C:\Users\Evita\AppData\Local\CRE deleted C:\Users\Evita\AppData\Local\SearchProtect deleted C:\Users\Evita\AppData\Local\DealPlyLive deleted C:\Users\Evita\AppData\Local\SwvUpdater deleted C:\Users\Evita\AppData\Local\Conduit deleted C:\Users\Evita\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SkypEmoticons deleted C:\Users\Evita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly deleted C:\windows\SysNative\Tasks\BackgroundContainer Startup Task deleted C:\Windows\Tasks\Dealply.job deleted C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job deleted C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job deleted C:\windows\SysNative\Tasks\Dealply deleted C:\windows\SysNative\Tasks\DealPlyLiveUpdateTaskMachineCore deleted C:\windows\SysNative\Tasks\DealPlyLiveUpdateTaskMachineUA deleted C:\windows\SysNative\Tasks\DealPlyUpdate deleted C:\Users\Evita\AppData\LocalLow\DVDVideoSoftTB deleted C:\Users\Evita\AppData\LocalLow\Search Settings deleted C:\Users\Evita\AppData\LocalLow\uTorrentBar_NL deleted C:\Users\Evita\AppData\LocalLow\PriceGong deleted C:\Users\Evita\AppData\LocalLow\Conduit deleted C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Application Updater deleted C:\Windows\wininit.ini deleted C:\Windows\tasks\AmiUpdXp.job deleted C:\windows\SysNative\tasks\ElectroLyrics-16-chromeinstaller deleted C:\windows\SysNative\tasks\ElectroLyrics-16-codedownloader deleted C:\windows\SysNative\tasks\ElectroLyrics-16-enabler deleted C:\windows\SysNative\tasks\ElectroLyrics-16-firefoxinstaller deleted C:\windows\SysNative\tasks\ElectroLyrics-16-updater deleted C:\Windows\tasks\ElectroLyrics-16-chromeinstaller.job deleted C:\Windows\tasks\ElectroLyrics-16-codedownloader.job deleted C:\Windows\tasks\ElectroLyrics-16-enabler.job deleted C:\Windows\tasks\ElectroLyrics-16-firefoxinstaller.job deleted C:\Windows\tasks\ElectroLyrics-16-updater.job deleted "C:\Users\Evita\AppData\Local\{9F8D4FB1-2199-4B72-BA8A-4B63BF46EA9A}" deleted "C:\Users\Evita\AppData\Roaming\SkypEmoticons\Res.dll" deleted "C:\Users\Evita\AppData\Roaming\SkypEmoticons\SE.exe" deleted "C:\Users\Evita\AppData\Roaming\SkypEmoticons" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2013-10-23 20:39:58 50735147AB8254BEF4D8A0723CBA9BF6 941022716 ----a-w- C:\Windows\MEMORY.DMP ====== C:\Users\Evita\AppData\Local\Temp ==== 2013-11-01 19:22:05 1A8438854DD15E4389F5BDEF502C369D 4216104 ----a-w- C:\Users\Evita\AppData\Local\Temp\ConduitEngine.dll 2013-11-01 18:56:39 EF7D5227360E42058D25F27D9DB95DE0 648472 ----a-w- C:\Users\Evita\AppData\Local\Temp\sSetup-se.exe 2013-11-01 18:48:37 9FB9D49C2DB7EDD1084AB765D619F5C6 66368 ----a-w- C:\Users\Evita\AppData\Local\Temp\utt17D8.tmp.exe 2013-11-01 18:48:14 24AEB20C4D857A431FE82AAC1A95C005 902736 ----a-w- C:\Users\Evita\AppData\Local\Temp\uttBF2E.tmp.exe 2013-11-01 13:38:02 AA023839E9DFBB84A6F446889994344F 116608 ----a-w- C:\Users\Evita\AppData\Local\Temp\fullpackage_temp\Baofeng.exe 2013-11-01 13:38:02 0D1FC3BFF64CD7E7E44C8BC8FC115F72 93184 ----a-w- C:\Users\Evita\AppData\Local\Temp\fullpackage_temp\UpDate.dll ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== ====== C:\Windows\Sysnative\drivers ===== ====== C:\Windows\Tasks ====== 2013-11-08 19:38:49 63A3476396B36FFECD8E4011EB1431CE 3128 ----a-w- C:\Windows\Sysnative\Tasks\{F68F744F-DB1D-4C28-8F44-B45BB69C2F1A} 2013-11-01 18:56:31 D328E2DC96648974EA93D6E6A35EC7B9 2694 ----a-w- C:\Windows\Sysnative\Tasks\ss u helper-S-9665547 2013-11-01 18:56:31 94E3CABF025E183C7A5934AAAE82A657 448 ---ha-w- C:\Windows\Tasks\ss u helper-S-9665547.job ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2013-11-08 18:49:46 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2013-11-01 18:56:23 -------- d-----w- C:\PROGRA~2\YoutubeAdblocker 2013-11-01 18:56:20 -------- d-----w- C:\PROGRA~2\DownLoAd akeepper 2013-11-01 18:51:59 -------- d-----w- C:\PROGRA~2\Registry Helper ======= C: ===== ====== C:\Users\Evita\AppData\Roaming ====== 2013-11-01 19:16:26 -------- d-----w- C:\Users\Evita\AppData\Local\Juniper Networks 2013-11-01 18:56:39 -------- d-----w- C:\Users\Evita\AppData\Locallow\{092147FB-BDAD-CD05-F806-B261373EC37A} 2013-11-01 18:56:23 -------- d-----w- C:\Users\Evita\AppData\Locallow\{0168B7A0-C191-DE75-5D2D-DF1B66629E1E} 2013-11-01 18:56:21 -------- d-----w- C:\Users\Evita\AppData\Local\Packages 2013-11-01 18:56:20 -------- d-----w- C:\Users\Evita\AppData\Locallow\{B1EE6749-C482-03C0-41F4-70AE13E026B0} 2013-11-01 18:50:58 -------- d-----w- C:\Users\Evita\AppData\Locallow\ElectroLyrics-16 2013-10-12 15:22:00 -------- d-----w- C:\Users\Evita\AppData\Locallow\WhiteSmoke_New_V6 ====== C:\Users\Evita ====== 2013-11-08 18:49:12 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\Evita\Downloads\RSITx64.exe 2013-11-01 18:56:24 -------- d-----w- C:\ProgramData\YoutubeAdblocker 2013-11-01 18:56:21 -------- d-----w- C:\ProgramData\DownLoAd akeepper 2013-11-01 18:56:21 -------- d-----w- C:\ProgramData\4625d012e49e8612 2013-11-01 18:52:18 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registry Helper 2013-10-29 14:02:42 17945562CC6860B3A58DE663F077F2FF 153120 ----a-w- C:\Users\Evita\Downloads\het vonnis__3039_i113378277_il1700684.exe 2013-10-29 13:30:42 69633E371112907EA6092BC06D0510A9 301216 ----a-w- C:\Users\Evita\Downloads\Het_Vonnis[2013]DVDRip_XviD[Belgium] (1).exe 2013-10-29 13:23:48 69633E371112907EA6092BC06D0510A9 301216 ----a-w- C:\Users\Evita\Downloads\Het_Vonnis[2013]DVDRip_XviD[Belgium].exe ====== C: exe-files == 2013-11-08 18:49:47 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Evita.exe 2013-11-08 18:49:12 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\Evita\Downloads\RSITx64.exe 2013-11-01 22:30:24 C8F51ACDAE6E1178985EA06B03B76E45 229288 ----a-w- C:\Users\Evita\AppData\Roaming\Dropbox\bin\DropboxUninstaller.exe 2013-11-01 22:29:06 273653EE7F9201F31834A9E6C5CDCF62 29769432 ----a-w- C:\Users\Evita\AppData\Roaming\Dropbox\bin\Dropbox.exe 2013-11-01 21:37:53 F817D8021352B78432F595771F6A8D2D 375072 ----a-w- C:\Users\Evita\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibcgjcbeckcdemelifnledhihpaighfk\10.22.0.588_0\nativeMessaging\TBMessagingHost.exe === C: other files == ==== Folders in C:\ProgramData 0-6 Months Old ====================== 2013-11-01 18:56:21 -------- d-----w- C:\ProgramData\4625d012e49e8612 2013-11-01 18:56:21 -------- d-----w- C:\ProgramData\DownLoAd akeepper 2013-11-01 18:56:24 -------- d-----w- C:\ProgramData\YoutubeAdblocker ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{BBDA0591-3099-440a-AA10-41764D9DB4DB}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_19.1.0.28\IPSFFPlgn" [01/12/2012 18:55] ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions cjofdnhdkbflacojpfpkchgafjahijbb - C:\Users\Evita\AppData\Local\Temp\crxADD1.tmp[] ibcgjcbeckcdemelifnledhihpaighfk - C:\Users\Evita\AppData\Local\CRE\ibcgjcbeckcdemelifnledhihpaighfk.crx[] ifohbjbgfchkkfhphahclmkpgejiplfo - C:\Users\Evita\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx[] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions ibcgjcbeckcdemelifnledhihpaighfk - C:\Users\Evita\AppData\Local\CRE\ibcgjcbeckcdemelifnledhihpaighfk.crx[] nikpibnbobmbdbheedjfogjlikpgpnhp - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx[12/12/2012 18:51] ElectroLyrics-16 - Evita - Default\Extensions\hemfpepmlfpoeaopamikcgielgbdfndp WhiteSmoke New V6 - Evita - Default\Extensions\ibcgjcbeckcdemelifnledhihpaighfk Select City - Evita - Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo DVDVideoSoft Browser Extension - Evita - Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp Google Wallet - Evita - Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda ==== Chrome Fix ====================== C:\Users\Evita\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage deleted successfully C:\Users\Evita\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage-journal deleted successfully C:\Users\Evita\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibcgjcbeckcdemelifnledhihpaighfk deleted successfully C:\Users\Evita\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo deleted successfully C:\Users\Evita\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ifohbjbgfchkkfhphahclmkpgejiplfo_0.localstorage deleted successfully C:\Users\Evita\AppData\Local\Google\Chrome\User Data\Default\Extensions\hemfpepmlfpoeaopamikcgielgbdfndp deleted successfully C:\Users\Evita\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hemfpepmlfpoeaopamikcgielgbdfndp_0.localstorage deleted successfully C:\Users\Evita\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hemfpepmlfpoeaopamikcgielgbdfndp_0.localstorage-journal deleted successfully C:\Users\Evita\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_hemfpepmlfpoeaopamikcgielgbdfndp_0 deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.be/" "Default_Page_URL"="http://start.qone8.com/?type=hp&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://start.qone8.com/web/?type=ds&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802&q={searchTerms}" "Default_Page_URL"="http://start.qone8.com/?type=hp&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802" "Start Page"="http://websearch.search-guide.info/?pid=969&r=2013/11/01&hid=15226878229854052771&lg=EN&cc=BE&unqvl=40" "Search Page"="http://start.qone8.com/web/?type=ds&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802&q={searchTerms}" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://start.qone8.com/web/?type=ds&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802&q={searchTerms}" "Default_Page_URL"="http://start.qone8.com/?type=hp&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802" "Start Page"="http://websearch.search-guide.info/?pid=969&r=2013/11/01&hid=15226878229854052771&lg=EN&cc=BE&unqvl=40" "Search Page"="http://start.qone8.com/web/?type=ds&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802&q={searchTerms}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="https://www.google.be/" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87775fdb-6972-41f9-ae51-8326e38cb206} deleted successfully HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{87775fdb-6972-41f9-ae51-8326e38cb206} deleted successfully HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{da7f5ae1-3be3-43c0-8098-c1d183616e97} deleted successfully HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{da7f5ae1-3be3-43c0-8098-c1d183616e97} deleted successfully HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411411152} deleted successfully HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9cf699ca-2174-4ed8-bec1-ba82095edce0} deleted successfully HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9cf699ca-2174-4ed8-bec1-ba82095edce0} deleted successfully HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{092147FB-BDAD-CD05-F806-B261373EC37A} deleted successfully HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{092147FB-BDAD-CD05-F806-B261373EC37A} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{87775fdb-6972-41f9-ae51-8326e38cb206} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{87775fdb-6972-41f9-ae51-8326e38cb206} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{da7f5ae1-3be3-43c0-8098-c1d183616e97} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{da7f5ae1-3be3-43c0-8098-c1d183616e97} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110411411152} deleted successfully HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110411411152} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{11111111-1111-1111-1111-110411411152} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411411152} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411411152} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{9cf699ca-2174-4ed8-bec1-ba82095edce0} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9cf699ca-2174-4ed8-bec1-ba82095edce0} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{092147FB-BDAD-CD05-F806-B261373EC37A} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{092147FB-BDAD-CD05-F806-B261373EC37A} deleted successfully HKEY_CLASSES_ROOT\CLSID\{092147FB-BDAD-CD05-F806-B261373EC37A} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{092147FB-BDAD-CD05-F806-B261373EC37A} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{092147FB-BDAD-CD05-F806-B261373EC37A} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{092147FB-BDAD-CD05-F806-B261373EC37A} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{da7f5ae1-3be3-43c0-8098-c1d183616e97} deleted successfully HKEY_USERS\S-1-5-21-4046708470-961614972-545868202-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{da7f5ae1-3be3-43c0-8098-c1d183616e97} deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\internet explorer\urlsearchhooks\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\internet explorer\urlsearchhooks\{87775fdb-6972-41f9-ae51-8326e38cb206} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{87775fdb-6972-41f9-ae51-8326e38cb206} deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\internet explorer\urlsearchhooks\{da7f5ae1-3be3-43c0-8098-c1d183616e97} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{da7f5ae1-3be3-43c0-8098-c1d183616e97} deleted successfully ==== shortcuts on Users Desktops ====================== C:\Users\Evita\Desktop\Any Video Converter.lnk - C:\Program Files (x86)\AnvSoft\Any Video Converter\AVCFree.exe C:\Users\Evita\Desktop\Dropbox.lnk - C:\Users\Evita\AppData\Roaming\Dropbox\bin\Dropbox.exe /home C:\Users\Evita\Desktop\Free YouTube to MP3 Converter.lnk - C:\Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Evita\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://start.qone8.com/?type=sc&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802 C:\Users\Evita\Desktop\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802 C:\Users\Evita\Desktop\Ontspanning - Snelkoppeling.lnk - C:\Users\Evita\Desktop\µTorrent.lnk - ==== shortcuts on All Users Desktop ====================== C:\Users\Public\Desktop\Acer GameZone Console.lnk - C:\Program Files (x86)\Acer GameZone\GameConsole\Acer Game Console.exe C:\Users\Public\Desktop\Acer Registration.lnk - C:\Program Files (x86)\Acer\Registration\GREG.exe C:\Users\Public\Desktop\Acer Store.lnk - C:\Program Files (x86)\Acer Accessory Store\StartUrl.exe http://store.acer-euro.com/be?utm_source=Icon&utm_medium=Icon&utm_campaign=Acer%2BInternal C:\Users\Public\Desktop\clear.fi Tutorial.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe "c:\Users\Public\Videos\clear.fi_tutorial_1125.wmv" /fullscreen C:\Users\Public\Desktop\Epson Easy Photo Print.lnk - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPQuicker.exe C:\Users\Public\Desktop\EPSON Scan.lnk - C:\Windows\twain_32\escndv\escndv.exe C:\Users\Public\Desktop\EPSON SX218 Series Handboek.lnk - C:\Program Files (x86)\epson\TpManual\EPSON SX218 Series\nl\Useg\index.htm C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk - C:\Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Public\Desktop\Internetbrowser selecteren.lnk - C:\Windows\System32\browserchoice.exe /launch C:\Users\Public\Desktop\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk - C:\Program Files (x86)\McAfee Security Scan\2.0.189\mcuicnt.exe SecurityScanner.dll C:\Users\Public\Desktop\Norton AntiVirus.lnk - C:\Program Files (x86)\Norton AntiVirus\Engine64\19.9.1.14\uistub.exe C:\Users\Public\Desktop\Norton Online Backup.lnk - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe OPEN C:\Users\Public\Desktop\QuickTime Player.lnk - C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe C:\Users\Public\Desktop\Registry Helper.lnk - C:\Program Files (x86)\Registry Helper\RegistryHelper.exe C:\Users\Public\Desktop\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Public\Desktop\VLC media player.lnk - C:\Program Files (x86)\VideoLAN\VLC\vlc.exe C:\Users\Public\Desktop\DVDVideoSoft\Free YouTube to MP3 Converter.lnk - C:\Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\Public\Desktop\DVDVideoSoft\Log Report.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\DVSSysReport.exe C:\Users\Public\Desktop\DVDVideoSoft\Rocket Subscription.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\SubscriptionOffer.exe ==== shortcuts in Users Start Menu ====================== C:\Users\Evita\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk - C:\Users\Evita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk - C:\Program Files\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802 C:\Users\Evita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802 C:\Users\Evita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802 C:\Users\Evita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox\Dropbox.lnk - C:\Users\Evita\AppData\Roaming\Dropbox\bin\Dropbox.exe /home C:\Users\Evita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk - C:\Users\Evita\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Log Report.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\DVSSysReport.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Rocket Subscription.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\SubscriptionOffer.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Uninstall.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\Uninstall.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Programs\Free YouTube to MP3 Converter.lnk - C:\Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://start.qone8.com/?type=sc&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\Silverlight.Configuration.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registry Helper\Registry Helper.lnk - C:\Program Files (x86)\Registry Helper\RegistryHelper.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registry Helper\Visit our Website.lnk - C:\Program Files (x86)\Registry Helper\Registry Helper.url ==== shortcuts in Quick Launch ====================== C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://start.qone8.com/?type=sc&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802 C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802 C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk - C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\Windows\system32\control.exe C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Calculator.lnk - C:\Windows\system32\calc.exe C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://start.qone8.com/?type=sc&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802 C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://start.qone8.com/?type=sc&ts=1383331892&from=amt&uid=WDCXWD6400BPVT-22HXZT1_WD-WX21A110480204802 C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Microsoft Word 2010.lnk - C:\Windows\Installer\{90140000-003D-0000-0000-0000000FF1CE}\wordicon.exe C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Norton AntiVirus.lnk - C:\Program Files (x86)\Norton AntiVirus\Engine64\19.9.1.14\uistub.exe C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Welcome Center.lnk - C:\Program Files (x86)\Acer\Welcome Center\OEMWelcomeCenter.exe C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\Windows\explorer.exe C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 ==== shortcuts After Repair ====================== C:\Users\Evita\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Evita\Desktop\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\Public\Desktop\Acer Store.lnk - C:\Program Files (x86)\Acer Accessory Store\StartUrl.exe C:\Users\Evita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Evita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\Evita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Evita\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6AFECAC2-50C9-80C0-6798-14D71EBAB0FC} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\cjofdnhdkbflacojpfpkchgafjahijbb deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ibcgjcbeckcdemelifnledhihpaighfk deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\ibcgjcbeckcdemelifnledhihpaighfk deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentBar_NL Toolbar deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD} deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelTBRunOnce deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Evita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Evita\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Evita\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Evita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Evita\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache is not empty, a reboot is needed ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Evita\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Evita\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found "C:\Users\Evita\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\JX7G57A4\static.muzu.tv" not found ==== EOF on vr 08/11/2013 at 21:12:39,97 ======================