Zoek.exe v5.0.0.0 Updated 07-February-2014 Tool run by Jasper on za 08-02-2014 at 10:25:56,38. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Jasper\Downloads\zoek (1).exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 8-2-2014 10:31:02 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\GreatSave4U deleted successfully C:\PROGRA~2\MSXML 4.0 deleted successfully C:\PROGRA~2\Pando Networks deleted successfully C:\PROGRA~2\PokerStars.EU deleted successfully C:\PROGRA~2\RoboSaver deleted successfully C:\PROGRA~2\Samsung deleted successfully C:\PROGRA~2\ssurf anud okeEp deleted successfully C:\PROGRA~2\VideoPlayerV3 deleted successfully C:\PROGRA~2\WebexpEnhancedV1 deleted successfully C:\PROGRA~2\COMMON~1\Symantec Shared deleted successfully C:\ProgramData\Babylon deleted successfully C:\ProgramData\Fighters deleted successfully C:\ProgramData\GreatSave4U deleted successfully C:\ProgramData\Oracle deleted successfully C:\ProgramData\RoboSaver deleted successfully C:\ProgramData\ssurf anud okeEp deleted successfully C:\Users\Jasper\AppData\Roaming\iPumper deleted successfully C:\Users\Jasper\AppData\Roaming\IrfanView deleted successfully C:\Users\Jasper\AppData\Roaming\Samsung deleted successfully C:\Users\Jasper\AppData\Roaming\TP deleted successfully C:\Users\Jasper\AppData\Roaming\Windows Live Writer deleted successfully C:\Users\Jasper\AppData\Local\CrashDumps deleted successfully C:\Users\Jasper\AppData\Local\GameSpy deleted successfully C:\Users\Jasper\AppData\Local\PackageAware deleted successfully C:\Users\Jasper\AppData\Local\PokerStars.EU deleted successfully C:\Users\Jasper\AppData\Local\Samsung deleted successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\CrashDumps deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2450652442-2951812239-2068010067-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_USERS\S-1-5-21-2450652442-2951812239-2068010067-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31ad400d-1b06-4e33-a59a-90c2c140cba0} deleted successfully HKEY_USERS\S-1-5-21-2450652442-2951812239-2068010067-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully HKEY_USERS\S-1-5-21-2450652442-2951812239-2068010067-1000\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{1d885f5e-3614-4c06-9a24-7f91db484c67} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1d885f5e-3614-4c06-9a24-7f91db484c67} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_CLASSES_ROOT\CLSID\{31ad400d-1b06-4e33-a59a-90c2c140cba0} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{31ad400d-1b06-4e33-a59a-90c2c140cba0} deleted successfully HKEY_CLASSES_ROOT\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-2450652442-2951812239-2068010067-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{1d885f5e-3614-4c06-9a24-7f91db484c67} deleted successfully HKEY_USERS\S-1-5-21-2450652442-2951812239-2068010067-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_USERS\S-1-5-21-2450652442-2951812239-2068010067-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{31ad400d-1b06-4e33-a59a-90c2c140cba0} deleted successfully HKEY_USERS\S-1-5-21-2450652442-2951812239-2068010067-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vToolbarUpdater17.3.0 deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vToolbarUpdater17.3.0 deleted successfully ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "bProtector Start Page"=- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "bProtectorDefaultScope"=- ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1d885f5e-3614-4c06-9a24-7f91db484c67}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Browser Infrastructure Helper"=- [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "mobilegeni daemon"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\GreatSave4U not found C:\Program Files (x86)\VideoPlayerV3 not found C:\ProgramData\ssurf anud okeEp not found C:\ProgramData\RoboSaver not found C:\ProgramData\GreatSave4U not found C:\Program Files (x86)\ssurf anud okeEp not found C:\Program Files (x86)\MediaPlayerV1 deleted C:\Program Files (x86)\Mobogenie deleted C:\ProgramData\AVG Security Toolbar deleted C:\ProgramData\AVG SafeGuard toolbar deleted C:\ProgramData\InstallMate deleted C:\Program Files (x86)\GS Supporter deleted C:\ProgramData\39b559e409962429 deleted C:\ProgramData\flncjniidokfidjhlgkgaffpeobefdaf deleted C:\Users\Jasper\AppData\LocalLow\{30B700C8-89FF-ACB6-BB4C-9843B33DCD20} deleted C:\Users\Jasper\AppData\LocalLow\{6A1132B2-341B-25AF-2C64-74B71447CE00} deleted C:\Users\Jasper\AppData\Local\Packages\windows_ie_ac_001\AC\{30B700C8-89FF-ACB6-BB4C-9843B33DCD20} deleted C:\Users\Jasper\AppData\Local\Packages\windows_ie_ac_001\AC\{6A1132B2-341B-25AF-2C64-74B71447CE00} deleted C:\PROGRA~2\TornTV.com deleted C:\Users\Jasper\daemonprocess.txt deleted C:\Users\Jasper\.android deleted C:\PROGRA~2\Better-Surf deleted C:\PROGRA~2\NCH Software\Components\NCHToolbars deleted C:\PROGRA~2\iLivid deleted C:\PROGRA~2\MyFree Codec deleted C:\PROGRA~2\PutLockerDownloader deleted C:\PROGRA~2\Conduit deleted C:\extensions.sqlite deleted C:\extensions.ini deleted C:\Users\Jasper\AppData\Roaming\Babylon deleted C:\Users\Jasper\AppData\Roaming\Dealply deleted C:\Users\Jasper\AppData\Roaming\File Scout deleted C:\Users\Jasper\AppData\Roaming\OpenCandy deleted C:\ProgramData\APN deleted C:\ProgramData\QuickSet deleted C:\ProgramData\SoftWarehouse deleted C:\ProgramData\Tarma Installer deleted C:\ProgramData\Premium deleted C:\Users\Jasper\AppData\Local\Ilivid Player deleted C:\Users\Jasper\AppData\Local\CRE deleted C:\Users\Jasper\AppData\Local\APN deleted C:\Users\Jasper\AppData\Local\NativeMessaging deleted C:\Users\Jasper\AppData\Local\PutLockerDownloader deleted C:\Users\Jasper\AppData\Local\Mobogenie deleted C:\Users\Jasper\AppData\Local\cache deleted C:\Users\Jasper\AppData\Local\SwvUpdater deleted C:\Users\Jasper\AppData\Local\Conduit deleted C:\Users\Jasper\AppData\Local\Google\Chrome\User Data\Default\bprotector web data deleted C:\Users\Jasper\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec deleted C:\Users\Jasper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com deleted C:\Users\Jasper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PutLockerDownloader.com deleted C:\Users\Jasper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tcbhn.lnk deleted C:\windows\SysNative\Tasks\BackgroundContainer Startup Task deleted C:\Windows\Tasks\Dealply.job deleted C:\windows\SysNative\Tasks\Dealply deleted C:\Users\Public\sdelev.tmp deleted C:\Users\Public\sdelevURL.tmp deleted C:\Users\Jasper\Downloads\avg_free_stb_all_2014_4259_cnet.exe deleted C:\Users\Jasper\Downloads\SopCast-3.5.0.exe deleted C:\Users\Jasper\Downloads\SopCast.zip deleted C:\Users\Jasper\Downloads\SoftonicDownloader_voor_bittorrent.exe deleted C:\Users\Jasper\Downloads\SoftonicDownloader_voor_pro-cycling-manager.exe deleted C:\Users\Jasper\Downloads\SoftonicDownloader_voor_samsung-kies (1).exe deleted C:\Users\Jasper\Downloads\SoftonicDownloader_voor_samsung-kies (2).exe deleted C:\Users\Jasper\Downloads\SoftonicDownloader_voor_samsung-kies (3).exe deleted C:\Users\Jasper\Downloads\SoftonicDownloader_voor_samsung-kies.exe deleted C:\Users\Jasper\Downloads\SoftonicDownloader_voor_system-explorer.exe deleted C:\Users\Jasper\AppData\LocalLow\AVG SafeGuard toolbar deleted C:\Users\Jasper\AppData\LocalLow\searchquband deleted C:\Users\Jasper\AppData\LocalLow\AskToolbar deleted C:\Users\Jasper\AppData\LocalLow\Delta deleted C:\Users\Jasper\AppData\LocalLow\Smartbar deleted C:\Users\Jasper\AppData\LocalLow\DataMngr deleted C:\Users\Jasper\AppData\LocalLow\Conduit deleted C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG SafeGuard toolbar deleted C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted C:\Windows\wininit.ini deleted C:\Windows\tasks\AmiUpdXp.job deleted C:\windows\SysNative\tasks\AmiUpdXp deleted C:\windows\SysNative\tasks\Escolade deleted C:\windows\SysNative\tasks\RunAsStdUser Task deleted C:\windows\SysNative\Tasks\BrowserProtect deleted C:\components deleted C:\user.js deleted C:\END deleted C:\Windows\SysWow64\searchplugins deleted C:\Windows\SysWow64\Extensions deleted C:\Users\Jasper\Documents\Mobogenie deleted C:\Users\Jasper\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\putlockerdownloader2@putlockerdownloader.com.xpi deleted C:\Users\Jasper\Desktop\PutLockerDownloader.lnk deleted C:\Users\Jasper\Downloads\the-wolf-of-wall-street-dut-5489259.exe deleted C:\Users\Jasper\Downloads\the-hobbit-an-unexpected-journey-dut-5381607.exe deleted C:\Users\Jasper\Downloads\the-family-dut-5433072 (1).exe deleted "C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP\WiseCustomCalla36.exe" deleted "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe" deleted "C:\Users\Jasper\AppData\Roaming\BrowserCompanion\tcbhn.exe" deleted "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe" deleted "C:\PROGRA~2\AVG SafeGuard toolbar\vprot.exe" deleted "C:\Users\Jasper\AppData\Roaming\BrowserCompanion\tcbhn.exe" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\MACTrackBarLib.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Microsoft.Practices.EnterpriseLibrary.Logging.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\QuickShare.exe" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\sgml.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\sidb.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\siem.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\sipb.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\sismlp.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ChromeLocalPlugin.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.FireFoxLocalPlugin.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\spbe.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\spbl.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\sppsm.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\spusm.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srau.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srbs.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srns.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srpdm.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srsbs.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srsbsau.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srut.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\nl\Smartbar.Resources.LanguageSettings.resources.dll" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\DNTInstaller\17.3.0\avgdttbx.dll" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\SiteSafetyInstaller\17.3.0\SiteSafety.dll" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\vToolbarUpdater\17.3.0\log4cplusU.dll" deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\vToolbarUpdater\17.3.0\loggingserver.exe" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\MACTrackBarLib.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Microsoft.Practices.EnterpriseLibrary.Logging.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\QuickShare.exe" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\sgml.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\sidb.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\siem.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\sipb.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\sismlp.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ChromeLocalPlugin.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.FireFoxLocalPlugin.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\spbe.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\spbl.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\sppsm.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\spusm.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srau.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srbs.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srns.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srpdm.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srsbs.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srsbsau.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srut.dll" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\nl\Smartbar.Resources.LanguageSettings.resources.dll" deleted "C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP" deleted "C:\Program Files (x86)\AVG SafeGuard toolbar" not deleted "C:\Users\Jasper\AppData\Local\Smartbar" not deleted "C:\Users\Jasper\AppData\Roaming\BrowserCompanion" not deleted "C:\Program Files (x86)\AVG SafeGuard toolbar" not deleted "C:\PROGRA~2\AVG SafeGuard toolbar" not deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search" not deleted "C:\Users\Jasper\AppData\Roaming\BrowserCompanion" not deleted "C:\ProgramData\Conduit" deleted "C:\Users\Jasper\AppData\Local\AVG SafeGuard toolbar" not deleted "C:\Users\Jasper\AppData\Local\Smartbar" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\nl" not deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\DNTInstaller" not deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\SiteSafetyInstaller" not deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\vToolbarUpdater" not deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\DNTInstaller\17.3.0" not deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\SiteSafetyInstaller\17.3.0" not deleted "C:\PROGRA~2\COMMON~1\AVG Secure Search\vToolbarUpdater\17.3.0" not deleted "C:\Users\Jasper\AppData\Local\AVG SafeGuard toolbar\Chrome" not deleted "C:\Users\Jasper\AppData\Local\AVG SafeGuard toolbar\Chrome\Default" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application" not deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\nl" not deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Jasper\AppData\Local\Temp ==== 2014-02-02 21:39:51 3D0FBB5BE79F98AEEE27ACA72206E755 20992 ----a-w- C:\Users\Jasper\AppData\Local\Temp\Smartbar\42c69e30-06dd-4c33-a064-675b8739e542\TurnOffProtectors.exe 2014-02-02 11:57:13 3B32CAA07D672F8A2E0DF5CB3A873F45 22704 ----a-w- C:\Users\Jasper\AppData\Local\Temp\ESGScanner.sys 2014-02-02 11:55:24 08882CAC56BB8B3FB01F6F387F2EFA4D 47329360 ----a-w- C:\Users\Jasper\AppData\Local\Temp\SHSetup.exe ====== Java Cache ===== 2014-01-10 18:32:18 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Users\Jasper\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\32\6c34baa0-250df521 ====== C:\Windows\SysWOW64 ===== ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== ====== C:\Windows\Sysnative\drivers ===== 2014-02-02 11:57:13 3B32CAA07D672F8A2E0DF5CB3A873F45 22704 ----a-w- C:\Windows\Sysnative\drivers\EsgScanner.sys 2014-01-15 09:55:06 DD253AFC3BC6CBA412342DE60C3647F3 30720 ----a-w- C:\Windows\Sysnative\drivers\usbuhci.sys 2014-01-15 09:55:06 DCA68B0943D6FA415F0C56C92158A83A 99840 ----a-w- C:\Windows\Sysnative\drivers\usbccgp.sys 2014-01-15 09:55:06 8D1196CFBB223621F2C67D45710F25BA 343040 ----a-w- C:\Windows\Sysnative\drivers\usbhub.sys 2014-01-15 09:55:06 18A85013A3E0F7E1755365D287443965 53248 ----a-w- C:\Windows\Sysnative\drivers\usbehci.sys 2014-01-15 09:55:06 12FEB33791920678F8433701C822BCFD 325120 ----a-w- C:\Windows\Sysnative\drivers\usbport.sys 2014-01-15 09:55:05 FFA06EF43987ED0DD42AD59B260C0C78 7808 ----a-w- C:\Windows\Sysnative\drivers\usbd.sys 2014-01-15 09:55:05 765A92D428A8DB88B960DA5A8D6089DC 25600 ----a-w- C:\Windows\Sysnative\drivers\usbohci.sys 2014-01-15 09:55:03 3555BA97171CD153118F73FDCCC8BFDE 376768 ----a-w- C:\Windows\Sysnative\drivers\netio.sys 2014-01-13 00:36:44 A1F53D2A00E64679A1D81B61D2333D06 46368 ----a-w- C:\Windows\Sysnative\drivers\avgtpx64.sys ====== C:\Windows\Tasks ====== 2014-02-02 11:57:14 EB475697294FA67A530147417D2DE707 3332 ----a-w- C:\Windows\Sysnative\Tasks\SpyHunter4Startup ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-02-08 08:28:27 -------- d-----w- C:\Program Files\trend micro 2014-02-02 11:56:59 -------- d-----w- C:\Program Files\Enigma Software Group 2014-01-21 11:44:50 -------- d-----w- C:\Program Files\Speccy ======= C:\PROGRA~2 ===== 2014-02-02 11:55:57 -------- d-----w- C:\PROGRA~2\COMMON~1\Wise Installation Wizard 2014-01-13 00:36:39 -------- d-----w- C:\PROGRA~2\COMMON~1\AVG Secure Search 2014-01-13 00:36:35 -------- d-----w- C:\PROGRA~2\AVG SafeGuard toolbar ======= C: ===== 2014-02-02 11:58:07 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\autoexec.bat ====== C:\Users\Jasper\AppData\Roaming ====== 2014-02-06 10:53:55 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Local\dumps 2014-02-02 11:57:04 -------- d-----w- C:\Users\Jasper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter 2014-01-21 18:07:18 -------- d-----w- C:\Users\Jasper\AppData\Roaming\Guild Wars 2 2014-01-13 00:36:58 -------- d-----w- C:\Users\Jasper\AppData\Local\AVG SafeGuard toolbar 2014-01-11 16:24:45 -------- d-----w- C:\Users\Jasper\AppData\Roaming\AVG2014 2014-01-11 16:23:55 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\AVG2014 2014-01-11 16:23:33 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Avg2014 2014-01-11 16:21:32 -------- d-----w- C:\Windows\SysNative\config\systemprofile\AppData\Local\Avg2014 2014-01-11 16:18:55 -------- d-----w- C:\Users\Jasper\AppData\Local\Avg2014 ====== C:\Users\Jasper ====== 2014-02-08 08:27:32 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\Jasper\Downloads\RSITx64.exe 2014-02-02 23:11:55 755246A3D44BFDB8A66DB8C19122724B 4721920 ----a-w- C:\Users\Jasper\Downloads\ccsetup410 (1).exe 2014-02-02 23:11:47 755246A3D44BFDB8A66DB8C19122724B 4721920 ----a-w- C:\Users\Jasper\Downloads\ccsetup410.exe 2014-02-02 11:55:00 E2204230A1FC502A780E96A3E7F3C8EF 728960 ----a-w- C:\Users\Jasper\Downloads\SpyHunter-Installer.exe 2014-01-29 22:11:07 02C1EE40968BAA67C3A785CDA9807125 262 --sha-r- C:\ProgramData\ntuser.pol 2014-01-21 18:08:23 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2 2014-01-21 11:44:52 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy 2014-01-11 16:23:32 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2014-01-11 16:22:56 -------- d-----w- C:\ProgramData\AVG2014 2014-01-10 23:02:01 -------- d-----r- C:\Users\Jasper\Google Drive 2014-01-10 23:00:26 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive ====== C: exe-files == === C: other files == 2014-02-02 11:58:07 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\autoexec.bat 2014-02-02 11:57:21 B97BE69C0A4230C285C087A726540F79 7538560 ----a-w- C:\Program Files\Enigma Software Group\SpyHunter\SH4.com ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-2450652442-2951812239-2068010067-1000\Software\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe /background" "Steam"="C:\Program Files (x86)\Steam\Steam.exe -silent" "uTorrent"="C:\Program Files (x86)\uTorrent\uTorrent.exe /MINIMIZED" "Spotify Web Helper"="C:\Users\Jasper\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "Spotify"="C:\Users\Jasper\AppData\Roaming\Spotify\Spotify.exe /uri spotify:autostart" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" @="C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" "BitTorrent"="C:\Users\Jasper\AppData\Roaming\BitTorrent\BitTorrent.exe /MINIMIZED" "Sony PC Companion"="C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe /Background" "GoogleDriveSync"="C:\Program Files (x86)\Google\Drive\googledrivesync.exe /autostart" "AVG-Secure-Search-Update_1213b"="C:\Users\Jasper\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=d62841db4cf347d1873ff123ccbdffd0-01ce204aa812893c7fbd388db363408b93b6ff6d /CMPID=1213b" [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "{90140000-0018-0413-0000-0000000FF1CE}"="C:\Windows\system32\cmd.exe /C del C:\ProgramData\Microsoft Help\Rgstrtn.lck /Q /A:H" "{90140000-0011-0000-0000-0000000FF1CE}"="C:\Windows\system32\cmd.exe /C del C:\ProgramData\Microsoft Help\Rgstrtn.lck /Q /A:H" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce] "{90140000-0018-0413-0000-0000000FF1CE}"="C:\Windows\system32\cmd.exe /C del C:\ProgramData\Microsoft Help\Rgstrtn.lck /Q /A:H" "{90140000-0011-0000-0000-0000000FF1CE}"="C:\Windows\system32\cmd.exe /C del C:\ProgramData\Microsoft Help\Rgstrtn.lck /Q /A:H" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Norton Online Backup"="C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun" "LManager"="C:\Program Files (x86)\Launch Manager\LManager.exe" "PWRISOVM.EXE"="C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup" "BCSSync"="C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe /DelayServices" "TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe -osboot" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "AVG_UI"="C:\Program Files (x86)\AVG\AVG2014\avgui.exe /TRAYONLY" "DivXMediaServer"="C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "vProt"="C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe /background" "Steam"="C:\Program Files (x86)\Steam\Steam.exe -silent" "uTorrent"="C:\Program Files (x86)\uTorrent\uTorrent.exe /MINIMIZED" "Spotify Web Helper"="C:\Users\Jasper\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "Spotify"="C:\Users\Jasper\AppData\Roaming\Spotify\Spotify.exe /uri spotify:autostart" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" @="C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" "BitTorrent"="C:\Users\Jasper\AppData\Roaming\BitTorrent\BitTorrent.exe /MINIMIZED" "Sony PC Companion"="C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe /Background" "GoogleDriveSync"="C:\Program Files (x86)\Google\Drive\googledrivesync.exe /autostart" "AVG-Secure-Search-Update_1213b"="C:\Users\Jasper\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=d62841db4cf347d1873ff123ccbdffd0-01ce204aa812893c7fbd388db363408b93b6ff6d /CMPID=1213b" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=" c:\\progra~2\\gssupp~1\\browsafe.dll" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AmIcoSinglun64"="C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "Acer ePower Management"="C:\Program Files\eMachines\eMachines Power Management\ePowerTray.exe" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " ==== Startup Folders ====================== 2012-10-20 17:47:25 1059 ----a-w- C:\Users\Jasper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk 2012-09-21 13:35:58 1940 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [25-12-2013 12:24] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [11-04-2013 16:53] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [11-04-2013 16:53] C:\Windows\tasks\Norton Security Scan for Jasper.job --ah----- [Undetermined Task] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\Norton Security Scan for Jasper" [C:\PROGRA~2\NORTON~2\Engine\372~1.5\Nss.exe] "C:\Windows\SysNative\tasks\RealUpgradeLogonTaskS-1-5-21-2450652442-2951812239-2068010067-1000" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe] "C:\Windows\SysNative\tasks\RealUpgradeScheduledTaskS-1-5-21-2450652442-2951812239-2068010067-1000" [C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe] "C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe] "C:\Windows\SysNative\tasks\SpyHunter4Startup" ["C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe"] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] "C:\Windows\SysNative\tasks\Recovery Management\Burn Notification" [C:\Program Files\eMachines\eMachines Recovery Management\NotificationCenter\Notification.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "ext@MediaPlayerV1alpha508.net"="C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha508\ff" [] ==== Firefox Extensions ====================== ==== Firefox Plugins ====================== ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions bodddioamolcibagionmmobehnbhiakf - C:\Program Files (x86)\BrowserCompanion\blabbers-ch.crx[] dedmngkbaffkenlfdcbganndoghblmap - C:\Program Files (x86)\BetterSurf\ch\Chrome.crx[11-11-2013 10:58] dnnajmlhehgnkclpdlggknanmcplloej - C:\Program Files (x86)\PutLockerDownloader\PutLockerDownloader10.crx[] effmnknpfaiehkmalhaggnbglpbkhane - C:\Users\Jasper\AppData\Local\CRE\effmnknpfaiehkmalhaggnbglpbkhane.crx[] gclijllifhfpomppedeljakfegbcpojn - C:\Users\Jasper\AppData\Local\Temp\ccex.crx[] jfmjfhklogoienhpfnppmbcbjfjnkonk - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx[13-08-2012 09:46] kekfoodhbhpjhjcdecjngamojfhknooc - C:\Users\Jasper\AppData\Roaming\iPumper\extension_chrome.crx[] ndibdjnfmopecpmkdieinmbadjfpblof - C:\ProgramData\AVG SafeGuard toolbar\ChromeExt\17.3.0.49\avg.crx[] pkmpcdbgnfjfeelcpebpkflcmbkclfho - C:\Users\Jasper\AppData\Local\CRE\pkmpcdbgnfjfeelcpebpkflcmbkclfho.crx[] poheodfamflhhhdcmjfeggbgigeefaco - C:\Program Files (x86)\Better-Surf\ch\Chrome.crx[] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions amfclgbdpgndipgoegfpkkgobahigbcl - C:\Users\Jasper\AppData\Local\Smartbar/Application\1Extension.crx[] apdfllckaahabafndbhieahigkjlhalf - C:\Users\Jasper\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx[11-01-2014 00:00] effmnknpfaiehkmalhaggnbglpbkhane - C:\Users\Jasper\AppData\Local\CRE\effmnknpfaiehkmalhaggnbglpbkhane.crx[] pkmpcdbgnfjfeelcpebpkflcmbkclfho - C:\Users\Jasper\AppData\Local\CRE\pkmpcdbgnfjfeelcpebpkflcmbkclfho.crx[] greatsavieer - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - Administrator\AppData\Local\Torch\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - Administrator\AppData\Local\Torch\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - Administrator\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - Administrator\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - ASPNET\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - ASPNET\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - ASPNET\AppData\Local\Torch\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - ASPNET\AppData\Local\Torch\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - ASPNET\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - ASPNET\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - Gast\AppData\Local\Torch\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - Gast\AppData\Local\Torch\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - Gast\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - Gast\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - HomeGroupUser$\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - HomeGroupUser$\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc Google Drive - Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf BetterSurf - Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\dedmngkbaffkenlfdcbganndoghblmap AdBlock - Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom RealPlayer HTML5Video Downloader Extension - Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk Media Player - Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\llpabpecgokncfojoiplifkhcpaajena Google Wallet - Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda greatsavieer - Jasper\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - Jasper\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - Jasper\AppData\Local\Torch\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - Jasper\AppData\Local\Torch\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc greatsavieer - Jasper\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn ssurf anud okeEp - Jasper\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc ==== Chrome Fix ====================== C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx deleted successfully C:\Users\Jasper\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bodddioamolcibagionmmobehnbhiakf_0.localstorage deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\Administrator\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\ASPNET\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\ASPNET\AppData\Local\Torch\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\ASPNET\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\Gast\AppData\Local\Torch\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\Gast\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\HomeGroupUser$\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\Jasper\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\Jasper\AppData\Local\Torch\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\Jasper\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\jjklkipdoaenikilhhookgcmkkajfklc deleted successfully C:\Users\Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\llpabpecgokncfojoiplifkhcpaajena deleted successfully C:\Users\Jasper\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\Administrator\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\ASPNET\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\ASPNET\AppData\Local\Torch\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\ASPNET\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\Gast\AppData\Local\Torch\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\Gast\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\HomeGroupUser$\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\Jasper\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\Jasper\AppData\Local\Torch\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully C:\Users\Jasper\AppData\Local\COMODO\Dragon\User Data\Default\Extensions\gebdeklbcfcbidjjaaiennckkgefajnn deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a8901593-1166-422c-89ed-0860dc37e277&searchtype=ds&q={searchTerms}&installDate=15/05/2013" "Search Bar"="http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a8901593-1166-422c-89ed-0860dc37e277&searchtype=ds&q={searchTerms}&installDate=15/05/2013" "Use Search Asst"="yes" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://isearch.brothersoft.com?f=undefined" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Start Page"="http://isearch.brothersoft.com?f=undefined" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "Default"="http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a8901593-1166-422c-89ed-0860dc37e277&searchtype=ds&q={searchTerms}&installDate=15/05/2013" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a8901593-1166-422c-89ed-0860dc37e277&searchtype=ds&q={searchTerms}&installDate=15/05/2013" "SearchAssistant"="http://feed.snapdo.com/?publisher=QuickObrw&dpid=QuickObrw&co=NL&userid=a8901593-1166-422c-89ed-0860dc37e277&searchtype=ds&q={searchTerms}&installDate=15/05/2013" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{006ee092-9658-4fd6-bd8e-a21a348e59f5}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" "Use Search Asst"="no" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2450652442-2951812239-2068010067-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E3C6B04-08FE-43BC-8E50-F90285024DEA} deleted successfully HKEY_USERS\S-1-5-21-2450652442-2951812239-2068010067-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E3C6B04-08FE-43BC-8E50-F90285024DEA} deleted successfully HKEY_USERS\S-1-5-21-2450652442-2951812239-2068010067-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8271B5D6-76D3-4ABF-AEB3-1721161C76BC} deleted successfully HKEY_USERS\S-1-5-21-2450652442-2951812239-2068010067-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8271B5D6-76D3-4ABF-AEB3-1721161C76BC} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{6E3C6B04-08FE-43BC-8E50-F90285024DEA} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{8271B5D6-76D3-4ABF-AEB3-1721161C76BC} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-2450652442-2951812239-2068010067-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{6E3C6B04-08FE-43BC-8E50-F90285024DEA} deleted successfully HKEY_USERS\S-1-5-21-2450652442-2951812239-2068010067-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{8271B5D6-76D3-4ABF-AEB3-1721161C76BC} deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ntfdsaftsfdfdxx@mozilla.org deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\12x3q@3244516.com deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\avg@toolbar deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaPlayerV1alpha508.net deleted successfully ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{DDAA6DC4-899B-FE67-31B1-6714BD876241} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{EF31FBF1-07A2-9A88-546A-F8095885BC60} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\4065f4fe-01a8-4c2f-ad8e-6427e6d82e13 deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\f4b234bc-79d2-450b-ad1f-73aabbb01f77 deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\f52e3fd5-2b3a-44b3-8c82-209cda8fec78 deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\bodddioamolcibagionmmobehnbhiakf deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\dnnajmlhehgnkclpdlggknanmcplloej deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\effmnknpfaiehkmalhaggnbglpbkhane deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\gclijllifhfpomppedeljakfegbcpojn deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\kekfoodhbhpjhjcdecjngamojfhknooc deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\poheodfamflhhhdcmjfeggbgigeefaco deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\effmnknpfaiehkmalhaggnbglpbkhane deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\pkmpcdbgnfjfeelcpebpkflcmbkclfho deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Jasper\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Jasper\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T85U1W2X will be deleted at reboot C:\Users\Jasper\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XME4X4LC will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\Jasper\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=3028 folders=577 292864798 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Users\Jasper\AppData\Local\Temp will be emptied at reboot C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Deleting Files / Folders ====================== "C:\Users\Jasper\AppData\Local\Smartbar\Application\Microsoft.Practices.EnterpriseLibrary.Logging.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\sidb.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\siem.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\sipb.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.FireFoxLocalPlugin.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\spbe.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\spbl.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srau.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srpdm.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srsbsau.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\srut.dll" deleted "C:\Users\Jasper\AppData\Local\Smartbar\Application\Microsoft.Practices.EnterpriseLibrary.Logging.dll" not found "C:\Users\Jasper\AppData\Local\Smartbar\Application\sidb.dll" not found "C:\Users\Jasper\AppData\Local\Smartbar\Application\siem.dll" not found "C:\Users\Jasper\AppData\Local\Smartbar\Application\sipb.dll" not found "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.FireFoxLocalPlugin.dll" not found "C:\Users\Jasper\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll" not found "C:\Users\Jasper\AppData\Local\Smartbar\Application\spbe.dll" not found "C:\Users\Jasper\AppData\Local\Smartbar\Application\spbl.dll" not found "C:\Users\Jasper\AppData\Local\Smartbar\Application\srau.dll" not found "C:\Users\Jasper\AppData\Local\Smartbar\Application\srpdm.dll" not found "C:\Users\Jasper\AppData\Local\Smartbar\Application\srsbsau.dll" not found "C:\Users\Jasper\AppData\Local\Smartbar\Application\srut.dll" not found "C:\Program Files (x86)\AVG SafeGuard toolbar" deleted "C:\Users\Jasper\AppData\Local\Smartbar" deleted "C:\Users\Jasper\AppData\Roaming\BrowserCompanion" deleted "C:\Program Files (x86)\AVG SafeGuard toolbar" not found "C:\PROGRA~2\AVG SafeGuard toolbar" not found "C:\PROGRA~2\COMMON~1\AVG Secure Search" deleted "C:\Users\Jasper\AppData\Roaming\BrowserCompanion" not found "C:\Users\Jasper\AppData\Local\AVG SafeGuard toolbar" deleted "C:\Users\Jasper\AppData\Local\Smartbar" not found "C:\Users\Jasper\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T85U1W2X" deleted "C:\Users\Jasper\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XME4X4LC" deleted ==== EOF on za 08-02-2014 at 11:58:10,03 ======================