Zoek.exe v5.0.0.0 Updated 02-June-2014 Tool run by Frans on zo 08/06/2014 at 13:58:12,69. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Frans\Downloads\zoek.exe [Scan all users] [Checkboxes used] ==== System Restore Info ====================== 8/06/2014 14:02:12 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Internet Explorer\SearchScopes\{A4ABEFA3-8D57-430C-91BB-5BC46526437C} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847} deleted successfully HKEY_CLASSES_ROOT\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{ae07101b-46d4-4a98-af68-0333ea26e113} deleted successfully ==== Running Processes ====================== C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\SysWOW64\svchost.exe C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe C:\Windows\SysWOW64\SAsrv.exe C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe C:\Program Files\Lenovo\AutoLock\ALCKRESI.exe C:\Program Files (x86)\Lexmark 1200 Series\LXCZbmgr.exe C:\Program Files (x86)\Lexmark 1200 Series\lxczbmon.exe C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE C:\Program Files (x86)\ASCOMP Software\BackUp Maker\bkmaker.exe C:\Windows\SysWOW64\jmdp\stij.exe C:\Program Files\AVAST Software\Avast\avastui.exe C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DeviceAgent.exe C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Lenovo\System Update\SUService.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe C:\Program Files (x86)\Windows Live\Mail\wlmail.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe C:\Windows\SysWOW64\ctfmon.exe C:\Users\Frans\Downloads\zoek.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Partner Service deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Partner Service deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CltMngSvc deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\CltMngSvc deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\APNMCP deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\APNMCP deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ibupdaterservice deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ibupdaterservice deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MapsGalaxy_39Service deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MapsGalaxy_39Service deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\videodownloadconverter_4zservice deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\videodownloadconverter_4zservice deleted successfully ==== FireFox Fix ====================== ProfilePath: C:\Users\Frans\AppData\Roaming\Mozilla\Firefox\Profiles\yzanzf9u.default user.js not found ---- Lines babsrc removed from prefs.js ---- user_pref("browser.startup.homepage", "http://www.doko-search.com/?babsrc=HP_ss_mib2&mntrId=AE03F0DEF1C068B2&affID=119357&tsp=4976"); ---- Lines ask.com modified from prefs.js ---- user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"4zffxtbr@VideoDownloadConverter_4z.com\":{\"descriptor\":\"C:\\\\ ---- Lines search.net removed from prefs.js ---- user_pref("browser.search.defaultenginename", "default-search.net"); user_pref("browser.search.order.1", "default-search.net"); user_pref("browser.search.selectedEngine", "default-search.net"); user_pref("keyword.URL", "http://www.default-search.net/search?sid=476&aid=135&itype=a&ver=12692&tm=327&src=ds&p="); ---- Lines ffxtbr modified from prefs.js ---- user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"4zffxtbr@VideoDownloadConverter_4z.com\":{\"descriptor\":\"C:\\\\ ---- FireFox user.js and prefs.js backups ---- prefs_20140806_2025_.backup ProfilePath: C:\Users\Frans\AppData\Roaming\Mozilla\Firefox\Profiles\extensions prefs.js not found user.js not found ---- FireFox user.js and prefs.js backups ---- ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "bProtector Start Page"=- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "bProtectorDefaultScope"=- ==== Deleting Files \ Folders ====================== C:\PROGRA~2\Mozilla Firefox\browser\searchplugins\default-search.xml deleted C:\PROGRA~2\Mozilla Firefox\defaults\preferences\autoconfig.js deleted C:\PROGRA~2\FTDownloader.com deleted C:\PROGRA~2\Delta deleted C:\PROGRA~2\SearchProtect deleted C:\PROGRA~2\CoolLyrics deleted C:\PROGRA~2\Optimizer Pro deleted C:\PROGRA~2\VideoDownloadConverter_4z deleted C:\PROGRA~2\Yontoo deleted C:\PROGRA~2\Smiley Bar for Facebook deleted C:\PROGRA~2\MapsGalaxy_39 deleted C:\PROGRA~2\Speed Analysis 2 deleted C:\PROGRA~2\Driver Pro deleted C:\PROGRA~2\GreenTree Applications deleted C:\PROGRA~2\SweetIM deleted C:\Users\Frans\AppData\Roaming\simplitec deleted C:\Users\Frans\AppData\Roaming\SimilarSites deleted C:\Users\Frans\AppData\Roaming\PlusWinks deleted C:\Users\Frans\AppData\Roaming\SpeedAnalysis2 deleted C:\Users\Frans\AppData\Roaming\Driver Pro deleted C:\Users\Frans\AppData\Roaming\BabSolution deleted C:\Users\Frans\AppData\Roaming\Babylon deleted C:\Users\Frans\AppData\Roaming\Yontoo deleted C:\Users\Frans\AppData\Roaming\File Scout deleted C:\Users\Frans\AppData\Roaming\Delta deleted C:\Users\Frans\AppData\Roaming\Systweak deleted C:\Users\Frans\AppData\Roaming\PerformerSoft deleted C:\Users\Frans\AppData\Roaming\Optimizer Pro deleted C:\PROGRA~3\Ask deleted C:\PROGRA~3\AskPartnerNetwork deleted C:\PROGRA~3\APN deleted C:\PROGRA~3\simplitec deleted C:\PROGRA~3\Partner deleted C:\PROGRA~3\IBUpdaterService deleted C:\PROGRA~3\Tarma Installer deleted C:\PROGRA~3\Babylon deleted C:\PROGRA~3\YTD Video Downloader deleted C:\PROGRA~3\Package Cache deleted C:\PROGRA~3\BoxUpdChk deleted C:\Users\Frans\AppData\Local\APN deleted C:\Users\Frans\AppData\Local\Giant Savings deleted C:\Users\Frans\AppData\Local\VideoDownloadConverter_4z deleted C:\Users\Frans\AppData\Local\SearchProtect deleted C:\Users\Frans\AppData\Local\avgchrome deleted C:\Users\Frans\AppData\Local\Software deleted C:\Users\Frans\AppData\Local\conduit deleted C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847} deleted C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data deleted C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Software deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Pro deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro deleted C:\Users\Frans\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard deleted C:\Users\Frans\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense deleted C:\Users\Frans\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FTDownloader.com deleted C:\Users\Frans\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Qtrax Player.lnk deleted C:\Windows\SysNative\roboot64.exe deleted C:\Windows\Tasks\SpeedUpMyPC.job deleted C:\windows\SysNative\Tasks\DealPly deleted C:\Users\Frans\Downloads\sysrc_trial_25044(1).exe deleted C:\Users\Frans\Downloads\sysrc_trial_25044(2).exe deleted C:\Users\Frans\Downloads\sysrc_trial_25044(3).exe deleted C:\Users\Frans\Downloads\sysrc_trial_25044(4).exe deleted C:\Users\Frans\Downloads\sysrc_trial_25044(5).exe deleted C:\Users\Frans\Downloads\sysrc_trial_25044(6).exe deleted C:\Users\Frans\Downloads\sysrc_trial_25044(7).exe deleted C:\Users\Frans\Downloads\sysrc_trial_25044.exe deleted C:\Users\Frans\Downloads\sysrc_trial_9407_dutch01(1).exe deleted C:\Users\Frans\Downloads\sysrc_trial_9407_dutch01.exe deleted C:\Users\Frans\Downloads\rcpsetupmarm1_marm1169649741fr_conduit.exe deleted C:\Users\Frans\Downloads\SoftonicDownloader_voor_cdburnerxp-pro.exe deleted C:\Users\Frans\Downloads\SoftonicDownloader_voor_foxit-reader.exe deleted C:\Users\Frans\Downloads\SoftonicDownloader_voor_speccy.exe deleted C:\Users\Frans\Downloads\SoftonicDownloader_voor_tuneaid.exe deleted C:\Users\Frans\Downloads\SoftonicDownloader_voor_vlc-media-player.exe deleted C:\Users\Frans\AppData\LocalLow\mixidj deleted C:\Users\Frans\AppData\LocalLow\VideoDownloadConverter_4z deleted C:\Users\Frans\AppData\LocalLow\IAC deleted C:\Users\Frans\AppData\LocalLow\Softonic deleted C:\Users\Frans\AppData\LocalLow\DataMngr deleted C:\Users\Frans\AppData\LocalLow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com deleted C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Toolbar4 deleted C:\windows\SysNative\Tasks\EPUpdater deleted C:\Windows\tasks\spmonitor.job deleted C:\windows\SysNative\tasks\spmonitor deleted C:\user.js deleted C:\END deleted C:\Windows\Syswow64\ARFC deleted C:\Windows\Syswow64\WNLT deleted C:\Windows\Syswow64\InstallUtil.InstallLog deleted C:\Windows\SysWow64\searchplugins deleted C:\Windows\SysWow64\Extensions deleted C:\Users\Frans\Documents\Optimizer Pro deleted C:\Users\Frans\AppData\Roaming\Mozilla\Firefox\Profiles\yzanzf9u.default\searchplugins\ask-search.xml deleted C:\Users\Frans\AppData\Roaming\Mozilla\Firefox\Profiles\yzanzf9u.default\searchplugins\default-search.xml deleted C:\Users\Frans\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\ftdownloader3@ftdownloader.com.xpi deleted C:\Windows\Installer\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D} deleted C:\Users\Frans\Desktop\Search the Web.url deleted C:\Users\Frans\Desktop\Optimizer Pro.lnk deleted C:\Users\Frans\Desktop\Driver Pro.lnk deleted C:\Users\Frans\Desktop\Qtrax Player.lnk deleted C:\Users\Frans\Desktop\SweetPcFix.url deleted C:\Users\Frans\AppData\Roaming\BabMaint.exe deleted C:\Users\Frans\hpqhvind.exe deleted C:\Users\Frans\AppData\Roaming\Mozilla\Extensions\pluswinks@PlusWinks deleted C:\Users\Frans\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com deleted C:\Users\Frans\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\extensions\39ffxtbr@MapsGalaxy_39.com deleted "C:\Users\Frans\AppData\Roaming\Mozilla\Firefox\Profiles\yzanzf9u.default\extensions\toolbar_ORJ-V7C@apn.ask.com.xpi" deleted "C:\windows\SysNative\dmwu.exe" deleted "C:\PROGRA~2\SaveSense\SaveSenseIE.dll" deleted "C:\PROGRA~2\SaveSense\SaveSenseIE.dll" deleted "C:\windows\SysNative\ljkb\ImHttpComm.dll" deleted "C:\windows\SysNative\ljkb\lmrn.dll" deleted "C:\windows\SysNative\ljkb\msvcp100.dll" deleted "C:\windows\SysNative\ljkb\msvcr100.dll" not deleted "C:\windows\SysNative\ljkb\stij.exe" deleted "C:\Windows\Syswow64\jmdp\ImHttpComm.dll" deleted "C:\Windows\Syswow64\jmdp\lmrn.dll" deleted "C:\Windows\Syswow64\jmdp\msvcp100.dll" deleted "C:\Windows\Syswow64\jmdp\msvcr100.dll" not deleted "C:\Windows\Syswow64\jmdp\stij.exe" deleted "C:\PROGRA~2\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" deleted "C:\PROGRA~2\SaveSense" not deleted "C:\PROGRA~2\SaveSense" not deleted "C:\PROGRA~2\AskPartnerNetwork" deleted "C:\Users\Frans\AppData\Roaming\DealPly" deleted "C:\Users\Frans\AppData\Local\Pokki" deleted "C:\windows\SysNative\ljkb" not deleted "C:\Windows\Syswow64\jmdp" not deleted "C:\PROGRA~2\AskPartnerNetwork\Toolbar" deleted "C:\PROGRA~2\AskPartnerNetwork\Toolbar\Updater" deleted ==== System Specs ====================== Windows: Windows 7 Home Premium Edition (64-bit) Service Pack 1 (Build 7601) Memory (RAM): 4008 MB CPU Info: Intel(R) Pentium(R) CPU B960 @ 2.20GHz CPU Speed: 2200,5 MHz Sound Card: Speakers (Conexant 20671 SmartA | Display Adapters: Intel(R) HD Graphics Family | Intel(R) HD Graphics Family | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver Monitors: 1x; Generic PnP Monitor | Screen Resolution: 1366 X 768 - 32 bit Network: Network Present Network Adapters: Microsoft Virtual WiFi Miniport Adapter | Realtek PCIe GBE Family Controller | 1x1 11b/g/n Wireless LAN PCI Express Half Mini Card Adapter CD / DVD Drives: 1x (D: | ) D: HL-DT-STDVDRAM GT33N Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 5 Button Wheel Mouse Present Hard Disks: C: 448,7GB | Q: 15,6GB Hard Disks - Free: C: 14,7GB | Q: 10,3MB Manufacturer *: LENOVO BIOS Info: AT/AT COMPATIBLE | 11/03/11 | LENOVO - 122 Time Zone: West-Europa (standaardtijd) Motherboard *: LENOVO 1143GZG Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: avast! Antivirus On-access scanning disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Anti-Spyware: avast! Antivirus disabled (Outdated) Default Browser: Firefox 29.0.1 Internet Explorer Version: 11.0.9600.17107 Mozilla Firefox version: 29.0.1 (x86 nl) Google Chrome version: 35.0.1916.114 Sun Java version: 1.7.0_55 (32-bit) Sun Java version: 1.7.0_55 (64-bit) Flash Player version: 13.0.0.214 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2014-05-11 17:12:21 0B5A0005C0BDF4A05174576AF80DEA04 43152 ----a-w- C:\Windows\avastSS.scr ====== C:\Users\Frans\AppData\Local\Temp ==== 2014-06-06 12:46:26 55350DA221E2CA825354E46C4A55F6FB 1422848 ----a-w- C:\Users\Frans\AppData\Local\Temp\speccycpuid.dll 2014-06-06 12:46:19 7388ACBFBF1817E9024C56CA9C046175 6335544 ----a-w- C:\Users\Frans\AppData\Local\Temp\nsnDD56\SpSetup.exe 2014-06-06 12:45:24 AC1177D245FB7E6237701006EFB064E9 111708 ----a-w- C:\Users\Frans\AppData\Local\Temp\SimBundD.exe 2014-06-06 12:45:24 54054FA5803AFD1D27D3CDF4470770CB 1529468 ----a-w- C:\Users\Frans\AppData\Local\Temp\spcon_1-2-0-0_row.exe 2014-05-29 11:11:48 78566EB93D0649F23957240E5A13FEB8 817152 ----a-w- C:\Users\Frans\AppData\Local\Temp\spcon\spcon_cn.exe 2014-05-28 14:23:39 B4D339A910082717CA465407572D468E 9052224 ----a-w- C:\Users\Frans\AppData\Local\Temp\Foxit Reader Updater.exe 2014-05-26 14:49:54 945D09C0925F771F907DEE3D0452ECF4 40960 ----a-w- C:\Users\Frans\AppData\Local\Temp\rtdrvmon.exe ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2014-06-08 06:26:35 7EAB131EBF08F0E9E64C96285BD7D493 264616 ----a-w- C:\Windows\SysWOW64\javaws.exe 2014-06-08 06:26:29 90B81156CF76103D107B60A7D02739C1 96168 ----a-w- C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-06-08 06:26:29 479099423E3058D55F1682F3330F9AA8 175016 ----a-w- C:\Windows\SysWOW64\java.exe 2014-06-08 06:26:29 26A414A2B7FC8AA5475CADB1189F1D02 175528 ----a-w- C:\Windows\SysWOW64\javaw.exe ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-05-28 10:58:18 0DED6DD34EC2877C72CC32624060019F 313256 ----a-w- C:\Windows\Sysnative\javaws.exe 2014-05-28 10:58:00 EB01E2AB90C1B8966ED27A6AD57D5BCA 189352 ----a-w- C:\Windows\Sysnative\javaw.exe 2014-05-28 10:58:00 176539F1D21C78D78D8C468413CFAF5A 108968 ----a-w- C:\Windows\Sysnative\WindowsAccessBridge-64.dll 2014-05-28 10:57:59 363FF136AC2C9A02E310E6A5E98ADFC0 189352 ----a-w- C:\Windows\Sysnative\java.exe ====== C:\Windows\Sysnative\drivers ===== 2014-05-15 05:27:03 1C2D8E18AA8FD50CD04C15CC27F7F5AB 155072 ----a-w- C:\Windows\Sysnative\drivers\ksecpkg.sys 2014-05-15 05:27:00 353009DEDF918B2A51414F330CF72DEC 95680 ----a-w- C:\Windows\Sysnative\drivers\ksecdd.sys 2014-05-11 17:12:24 340B0467E98A8C92697D73034DB4BCB7 29208 ----a-w- C:\Windows\Sysnative\drivers\aswHwid.sys ====== C:\Windows\Tasks ====== 2014-05-30 07:35:20 76E8B988328FD1AE437E5F4D765A7E3E 3248 ----a-w- C:\Windows\Sysnative\Tasks\{0CB6A476-7A5B-4AF4-AC5F-5CC8C33EBCEE} ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-06-08 06:36:34 -------- d-----w- C:\Program Files\trend micro 2014-06-06 12:46:06 -------- d-----w- C:\Program Files\Speccy 2014-06-04 07:24:57 -------- d-----w- C:\Program Files\iPod 2014-06-04 07:24:56 -------- d-----w- C:\Program Files\iTunes ======= C:\PROGRA~2 ===== 2014-06-06 12:46:03 -------- d-----w- C:\PROGRA~2\SiteLookup 2014-06-06 12:45:54 -------- d-----w- C:\PROGRA~2\SiteFinder 2014-06-04 07:24:56 -------- d-----w- C:\PROGRA~2\iTunes 2014-05-25 17:04:50 -------- d-----w- C:\PROGRA~2\Drivers Manager 2014-05-19 05:48:16 -------- d-----w- C:\PROGRA~2\COMMON~1\DESIGNER ======= C: ===== ====== C:\Users\Frans\AppData\Roaming ====== 2014-05-25 17:04:51 -------- d-----w- C:\Users\Frans\AppData\Roaming\Drivers Manager 2014-05-25 16:29:05 -------- d-----w- C:\Users\Frans\AppData\Roaming\EncryptStick 2014-05-19 14:08:32 2D09628F3B560B1E59F55EEF335DC278 158600 ----a-w- C:\Windows\sysWoW64\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-12 06:45:53 -------- d-sh--w- C:\Users\Frans\AppData\Locallow\EmieUserList 2014-05-12 06:45:38 -------- d-sh--w- C:\Users\Frans\AppData\Local\EmieUserList 2014-05-12 06:45:38 -------- d-sh--w- C:\Users\Frans\AppData\Local\EmieSiteList 2014-05-12 06:45:21 -------- d-----w- C:\Users\Frans\AppData\Roaming\DropboxMaster 2014-05-12 06:45:05 -------- d-----w- C:\Users\Frans\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-05-12 06:44:56 -------- d-sh--w- C:\Users\Frans\AppData\Locallow\EmieSiteList 2014-05-12 06:44:11 -------- d-----w- C:\Users\Frans\AppData\Roaming\Dropbox ====== C:\Users\Frans ====== 2014-06-08 06:30:45 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Frans\Downloads\RSITx64.exe 2014-06-08 06:26:10 17E19B0B12CBE7E6ECEE17A9EC08BEAA 3448184 ----a-w- C:\Users\Frans\Downloads\8ass82ww(2).exe 2014-06-08 06:25:40 17E19B0B12CBE7E6ECEE17A9EC08BEAA 3448184 ----a-w- C:\Users\Frans\Downloads\8ass82ww(1).exe 2014-06-08 06:17:48 17E19B0B12CBE7E6ECEE17A9EC08BEAA 3448184 ----a-w- C:\Users\Frans\Downloads\8ass82ww.exe 2014-06-06 12:45:24 A0E9A27B051ACEB918F7DBB88BBF3DB3 5552488 ----a-w- C:\Users\Frans\Desktop\spsetup123.exe 2014-06-04 07:26:14 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-06-04 07:24:56 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-05-26 14:17:37 0D9AB4986FE7108944C1199D9AAC7DBE 57036800 ----a-w- C:\Users\Frans\Downloads\cjq1200Win7en(1).exe 2014-05-26 13:34:10 A61A24E28CE5E961941D61C1D342AC39 4748896 ----a-w- C:\Users\Frans\Downloads\ccsetup414.exe 2014-05-25 17:04:54 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Drivers Manager 2014-05-19 06:33:15 -------- d-----w- C:\ProgramData\systemk 2014-05-13 09:11:04 -------- d-----r- C:\Windows\SysNative\config\systemprofile\Searches ====== C: exe-files == 2014-06-08 11:57:17 E72310FB9696FA0DA6E4233224A5BC06 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-391721705-2454154653-1063795786-1000\$IMOV32M.exe 2014-06-08 11:57:11 E3D8CAE24FC55CA9FF57F185336DA4E5 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-391721705-2454154653-1063795786-1000\$IQBDMW3.exe 2014-06-08 11:57:05 A90B25161B033B4B886218E378A846EE 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-391721705-2454154653-1063795786-1000\$I9WJXTH.exe 2014-06-08 11:57:00 B05CB88DD170E468F8B80AD3D64371F7 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-391721705-2454154653-1063795786-1000\$IA43W7H.exe 2014-06-08 11:37:56 352E8561E633B17ED22012366721FFDC 1285120 ----a-w- C:\$Recycle.Bin\S-1-5-21-391721705-2454154653-1063795786-1000\$RMOV32M.exe 2014-06-08 11:35:29 352E8561E633B17ED22012366721FFDC 1285120 ----a-w- C:\$Recycle.Bin\S-1-5-21-391721705-2454154653-1063795786-1000\$RA43W7H.exe 2014-06-08 11:35:29 352E8561E633B17ED22012366721FFDC 1285120 ----a-w- C:\$Recycle.Bin\S-1-5-21-391721705-2454154653-1063795786-1000\$R9WJXTH.exe 2014-06-08 11:35:28 352E8561E633B17ED22012366721FFDC 1285120 ----a-w- C:\$Recycle.Bin\S-1-5-21-391721705-2454154653-1063795786-1000\$RQBDMW3.exe 2014-06-08 08:08:48 CF8AD7DE47B8E336F39C1041939389C6 378984 ----a-w- C:\SWTOOLS\CARDREADER\8ASS82WW\setup.exe 2014-06-08 06:36:34 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Frans.exe 2014-06-08 06:35:42 E49D05F5F5A0D3344CBA91683197F177 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-391721705-2454154653-1063795786-1000\$I450YC2.exe 2014-06-08 06:35:34 B8589195F005CEDC6E1B266941783ED7 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-391721705-2454154653-1063795786-1000\$IBNAX0M.exe 2014-06-08 06:34:07 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\$Recycle.Bin\S-1-5-21-391721705-2454154653-1063795786-1000\$R450YC2.exe 2014-06-08 06:32:02 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\$Recycle.Bin\S-1-5-21-391721705-2454154653-1063795786-1000\$RBNAX0M.exe 2014-06-08 06:30:45 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Frans\Downloads\RSITx64.exe 2014-06-08 06:26:35 7EAB131EBF08F0E9E64C96285BD7D493 264616 ----a-w- C:\Windows\SysWOW64\javaws.exe 2014-06-08 06:26:29 479099423E3058D55F1682F3330F9AA8 175016 ----a-w- C:\Windows\SysWOW64\java.exe 2014-06-08 06:26:29 26A414A2B7FC8AA5475CADB1189F1D02 175528 ----a-w- C:\Windows\SysWOW64\javaw.exe 2014-06-08 06:26:21 E53D6E485A0302A9C7D5E0D4D3E3C8B0 145832 ----a-w- C:\Program Files (x86)\Java\jre7\bin\unpack200.exe 2014-06-08 06:26:21 5EBBDE8E4FA26B4DC2477EEFC580BBEC 16808 ----a-w- C:\Program Files (x86)\Java\jre7\bin\tnameserv.exe 2014-06-08 06:26:20 F4DED4130A0104B6A4ED9844208F180F 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\servertool.exe 2014-06-08 06:26:20 A88ABFD096E23B5560667BDC05917566 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\rmiregistry.exe 2014-06-08 06:26:20 971C6733A1AF11192C378CC736F85DCC 49576 ----a-w- C:\Program Files (x86)\Java\jre7\bin\ssvagent.exe 2014-06-08 06:26:20 6544D757CC478157D0B1A7752E51FE3B 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\policytool.exe 2014-06-08 06:26:20 2AAB5E6938B562D4A78C8DB5F8923142 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\rmid.exe 2014-06-08 06:26:20 1D512E4C00DDFC9D0D236E818991EF1B 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\orbd.exe 2014-06-08 06:26:20 11065E949C9640B42D0DE37CCF55F31C 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\pack200.exe 2014-06-08 06:26:19 F82ACDE93EC413733A4BE85BB34BEC14 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\java-rmi.exe 2014-06-08 06:26:19 EB80B1148FF046F466D1C671AF75D559 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\keytool.exe 2014-06-08 06:26:19 DA6CB7FCDE22F46C2A792F67033AF20D 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\ktab.exe 2014-06-08 06:26:19 9E7CB10B1373D7172AE87D597AC58C24 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\kinit.exe 2014-06-08 06:26:19 7EAB131EBF08F0E9E64C96285BD7D493 264616 ----a-w- C:\Program Files (x86)\Java\jre7\bin\javaws.exe 2014-06-08 06:26:19 76C9EFEA16CF2FAD41F6D6A37707A28B 68008 ----a-w- C:\Program Files (x86)\Java\jre7\bin\javacpl.exe 2014-06-08 06:26:19 60050CE9D89F59C0FE53C74BC78E6655 48040 ----a-w- C:\Program Files (x86)\Java\jre7\bin\jabswitch.exe 2014-06-08 06:26:19 479099423E3058D55F1682F3330F9AA8 175016 ----a-w- C:\Program Files (x86)\Java\jre7\bin\java.exe 2014-06-08 06:26:19 45A663489E1A24FE3696F689178C1041 182696 ----a-w- C:\Program Files (x86)\Java\jre7\bin\jqs.exe 2014-06-08 06:26:19 29869351791BADAC5BF5647F2E3FCA2E 16296 ----a-w- C:\Program Files (x86)\Java\jre7\bin\klist.exe 2014-06-08 06:26:19 26A414A2B7FC8AA5475CADB1189F1D02 175528 ----a-w- C:\Program Files (x86)\Java\jre7\bin\javaw.exe 2014-06-08 06:26:19 068C8B4DD85CA47817BECD77F07110EC 52648 ----a-w- C:\Program Files (x86)\Java\jre7\bin\jp2launcher.exe 2014-06-08 06:26:10 17E19B0B12CBE7E6ECEE17A9EC08BEAA 3448184 ----a-w- C:\Users\Frans\Downloads\8ass82ww(2).exe 2014-06-08 06:25:40 17E19B0B12CBE7E6ECEE17A9EC08BEAA 3448184 ----a-w- C:\Users\Frans\Downloads\8ass82ww(1).exe 2014-06-08 06:17:48 17E19B0B12CBE7E6ECEE17A9EC08BEAA 3448184 ----a-w- C:\Users\Frans\Downloads\8ass82ww.exe 2014-06-06 12:46:19 7388ACBFBF1817E9024C56CA9C046175 6335544 ----a-w- C:\Users\Frans\AppData\Local\Temp\nsnDD56\SpSetup.exe 2014-06-06 12:46:16 ACCFF193BF83CA1D84FC8CD72D263FB9 237640 ----a-w- C:\Users\Frans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\58A8S3PV\spstub[1].exe 2014-06-06 12:46:09 0B813086A3400AAFA1639D08823FBD46 145928 ----a-w- C:\Users\Frans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A8I3MIAX\sp-downloader[1].exe 2014-06-06 12:46:02 B08D26E839A3635C5E8113607FB0961A 48532 ----a-w- C:\Program Files (x86)\SiteFinder\sitefinder_uninstaller.exe 2014-06-06 12:45:52 39F138537879EA79961BD8FB281C09A4 225712 ----a-w- C:\Users\Frans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\58A8S3PV\sitefinder_installer[1].exe 2014-06-06 12:45:24 AC1177D245FB7E6237701006EFB064E9 111708 ----a-w- C:\Users\Frans\AppData\Local\Temp\SimBundD.exe 2014-06-06 12:45:24 A0E9A27B051ACEB918F7DBB88BBF3DB3 5552488 ----a-w- C:\Users\Frans\Desktop\spsetup123.exe 2014-06-06 12:45:24 54054FA5803AFD1D27D3CDF4470770CB 1529468 ----a-w- C:\Users\Frans\AppData\Local\Temp\spcon_1-2-0-0_row.exe 2014-06-06 12:35:45 DF493EB874A70F682500E390BABC806B 357712 ----a-w- C:\Users\Frans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0OV7N99R\SoftonicDownloader_voor_speccy.exe 2014-06-04 12:00:36 41580ACB0CE17E40C7DEADB5A87326C2 24392 ----a-w- C:\Program Files\CDBurnerXP\updater.exe 2014-06-04 07:19:01 580F8607FBD31312460BEB9CC6225662 77136 ----a-w- C:\Users\Frans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I97Q6MM1\SetupAdmin[1].exe 2014-06-04 07:19:01 580F8607FBD31312460BEB9CC6225662 77136 ----a-w- C:\ProgramData\Apple Computer\Installer Cache\iTunes 11.2.2.3\SetupAdmin.exe === C: other files == 2014-06-08 08:08:48 D6481828C5E6296942C6B441C481D60E 76288 ----a-w- C:\SWTOOLS\CARDREADER\8ASS82WW\Driver\risdxc86.sys 2014-06-08 08:08:48 5A227511ED22DDFEDF7EF7323C8F7D2F 101888 ----a-w- C:\SWTOOLS\CARDREADER\8ASS82WW\Driver\risdxc64.sys 2014-06-08 06:26:21 D89A382292CB7F22CD29D6E5D9A41CBF 18714 ----a-w- C:\Program Files (x86)\Java\jre7\lib\deploy\ffjcext.zip 2014-06-06 12:45:51 F07560500A2B48E0D0B78735E41F684F 54867 ----a-w- C:\Users\Frans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SZRF307Q\matchersite1.0[1].xpi ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Run] "Optimizer Pro"="C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe" "NTRedirect"="C:\Windows\SysWOW64\rundll32.exe C:\Users\Frans\AppData\Roaming\BabSolution\Shared\enhancedNT.dll,Run" "Driver Pro"="C:\Program Files (x86)\Driver Pro\DPLauncher.exe" "Uploader"="C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe" "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "Drivers Manager"="C:\Program Files (x86)\Drivers Manager\DMLauncher.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MobileBroadband"="C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent" "AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui" "ApnTBMon"="C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime" "DBAgent"="C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe /WinStart" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Optimizer Pro"="C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe" "NTRedirect"="C:\Windows\SysWOW64\rundll32.exe C:\Users\Frans\AppData\Roaming\BabSolution\Shared\enhancedNT.dll,Run" "Driver Pro"="C:\Program Files (x86)\Driver Pro\DPLauncher.exe" "Uploader"="C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe" "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "Drivers Manager"="C:\Program Files (x86)\Drivers Manager\DMLauncher.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_Dlls"="C:\\PROGRA~2\\SearchProtect\\SearchProtect\\bin\\SPVC32Loader.dll" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TpShocks"="TpShocks.exe" "SmartAudio"="C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t" "ForteConfig"="C:\Program Files\Conexant\ForteConfig\fmapp.exe" "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" "LENOVO.TPKNRRES"="C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe" "ALCKRESI.EXE"="C:\Program Files\Lenovo\AutoLock\ALCKRESI.EXE" "lxczbmgr.exe"="C:\Program Files (x86)\Lexmark 1200 Series\lxczbmgr.exe" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_Dlls"="C:\\PROGRA~2\\SearchProtect\\SearchProtect\\bin\\SPVC64Loader.dll" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ApnUpdater" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Ask.com\\Updater\\Updater.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LTT] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="LTT" "hkey"="HKCU" "command"="C:\\Program Files\\PC-Doctor\\EnableToolbarW32.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AdobeFlashPlayerUpdateSvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdate] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdatem] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gusvc] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\SkypeUpdate] ==== Startup Folders ====================== 2014-04-18 11:24:27 1436 ----a-w- C:\Users\Frans\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Belgacom Cloud.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [14/05/2014 14:37] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [27/01/2012 21:22] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [27/01/2012 21:22] C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job --a------ C:\Program Files\PC-Doctor\uaclauncher.exe [27/06/2011 17:06] C:\Windows\tasks\SystemToolsDailyTest.job --a------ C:\Program Files\PC-Doctor\uaclauncher.exe [27/06/2011 17:06] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\BackUp_Maker-Frans" ["C:\Program Files (x86)\ASCOMP Software\BackUp Maker\bkmaker.exe"] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\Frans DBAgent 2 0" ["C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe"] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\MCP" ["C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe"] "C:\Windows\SysNative\tasks\PCDEventLauncher" ["C:\Program Files\PC-Doctor\sessionchecker.exe"] "C:\Windows\SysNative\tasks\PCDoctorBackgroundMonitorTask" [C:\Program Files\PC-Doctor\uaclauncher.exe] "C:\Windows\SysNative\tasks\PMTask" [C:\PROGRA~2\ThinkPad\UTILIT~1\PwmIdTsv.exe] "C:\Windows\SysNative\tasks\Seagate_Install_Launch" [C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Dashboard.exe] "C:\Windows\SysNative\tasks\SystemToolsDailyTest" [C:\Program Files\PC-Doctor\uaclauncher.exe] "C:\Windows\SysNative\tasks\{D8AD8E2B-0F76-4C61-BB31-60C90C9ADF11}" [C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe] "C:\Windows\SysNative\tasks\{F7F4C2D8-36D2-49E2-A381-97CF3CA4981B}" [C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe] "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\SysNative\tasks\Lenovo\Lenovo Customer Feedback Program" ["%ProgramFiles%\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe"] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [11/05/2014 19:12] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Frans\AppData\Roaming\Mozilla\Firefox\Profiles\yzanzf9u.default - Linkey for Firefox - %ProfilePath%\extensions\extension@linkeyproject.com - Site Matcher - %ProfilePath%\extensions\matchersite@matchersite.com - SaveSense - %ProfilePath%\extensions\{2fab2e94-d6f9-42de-8839-3510cef6424b} - Settings Manager - %ProfilePath%\extensions\{E42AC5EF-EAFC-E69C-365F-EF5AF17A5D4D} AppDir: C:\Program Files (x86)\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Frans\AppData\Roaming\Mozilla\Firefox\Profiles\yzanzf9u.default A58DE0A570148AF5FF3512B2A340D09F - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll - Shockwave Flash ==== Deleted Firefox Extensions ====================== C:\Users\Frans\AppData\Roaming\Mozilla\Firefox\Profiles\yzanzf9u.default\extensions\{2fab2e94-d6f9-42de-8839-3510cef6424b} deleted ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions eooncjejnppfjjklapaamhcdmjbilmde - C:\Users\Frans\AppData\Roaming\BabSolution\CR\Delta.crx[] gaiilaahiahdejapggenmdmafpmbipje - No path found[] jcdgjdiieiljkfkdcloehkohchhpekkn - C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx[] lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx[17/01/2012 12:45] ndkhncnongaclekkbelchmeafffimifj - C:\Users\Frans\AppData\Local\Giant Savings\Chrome\Giant Savings.crx[] niapdbllcanepiiimjjndipklodoedlc - No path found[] ogccgbmabaphcakpiclgcnmcnimhokcj - C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetNT.crx[] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions gaiilaahiahdejapggenmdmafpmbipje - No path found[] Smart Display - Default\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbpohikckhbcljgombipcdoinkaedlfa Smart Display - Default User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbpohikckhbcljgombipcdoinkaedlfa Foxit Toolbar - Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaoiagmlcohkmjodefppbmpjdiocmh Speed Analysis 2 - Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgjkhjdcljddbedokogakmmdjgnbeanf Delta Toolbar - Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde DealPly - Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje SweetIM for Facebook - Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn MixiDj Chrome Toolbar - Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn Skype Click to Call - Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl Smiley Bar for Facebook - Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\mocblcnaofikinigmceddfghppkkjbog Giant Savings - Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndkhncnongaclekkbelchmeafffimifj Chrome In-App Payments service - Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda SweetPacks Chrome Extension - Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj Smart Display - Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbpohikckhbcljgombipcdoinkaedlfa ==== Chrome Fix ====================== C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde deleted successfully C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eooncjejnppfjjklapaamhcdmjbilmde_0.localstorage deleted successfully C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje deleted successfully C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gaiilaahiahdejapggenmdmafpmbipje_0.localstorage deleted successfully C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn deleted successfully C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndkhncnongaclekkbelchmeafffimifj deleted successfully C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndkhncnongaclekkbelchmeafffimifj_0.localstorage deleted successfully C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_ndkhncnongaclekkbelchmeafffimifj_0 deleted successfully C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj deleted successfully C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgjkhjdcljddbedokogakmmdjgnbeanf deleted successfully C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaoiagmlcohkmjodefppbmpjdiocmh deleted successfully C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpepfkjapeclaafmhoelccknpfedainn deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.be/" "Default_Page_URL"="http://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP" "Search Page"="http://feed.snap.do/?publisher=Tuguu&dpid=Tuguu&co=FR&userid=ce2c2e83-ea74-472f-a03d-2bbdae754986&searchtype=ds&q={searchTerms}&installDate=01/05/2013" "Search Bar"="http://feed.snap.do/?publisher=Tuguu&dpid=Tuguu&co=FR&userid=ce2c2e83-ea74-472f-a03d-2bbdae754986&searchtype=ds&q={searchTerms}&installDate=01/05/2013" "Use Search Asst"="yes" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "Default"="http://feed.snap.do/?publisher=Tuguu&dpid=Tuguu&co=FR&userid=ce2c2e83-ea74-472f-a03d-2bbdae754986&searchtype=ds&q={searchTerms}&installDate=01/05/2013" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl] "Default"="http://feed.snap.do/?publisher=Tuguu&dpid=Tuguu&co=FR&userid=ce2c2e83-ea74-472f-a03d-2bbdae754986&searchtype=ds&q={searchTerms}&installDate=01/05/2013" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "Default"="http://feed.snap.do/?publisher=Tuguu&dpid=Tuguu&co=FR&userid=ce2c2e83-ea74-472f-a03d-2bbdae754986&searchtype=ds&q={searchTerms}&installDate=01/05/2013" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://feed.snap.do/?publisher=Tuguu&dpid=Tuguu&co=FR&userid=ce2c2e83-ea74-472f-a03d-2bbdae754986&searchtype=ds&q={searchTerms}&installDate=01/05/2013" "SearchAssistant"="http://feed.snap.do/?publisher=Tuguu&dpid=Tuguu&co=FR&userid=ce2c2e83-ea74-472f-a03d-2bbdae754986&searchtype=ds&q={searchTerms}&installDate=01/05/2013" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="https://www.google.be/" "Use Search Asst"="no" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" {15C6ADEB-8776-4855-96EC-4222B716DC2A} (www.google.com) Google Url="https://www.google.com/search?q={searchTerms}" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7LENP_nlBE473" {EEE6C360-6118-11DC-9C72-001320C79847} Sweetpacks Search Url="http://mysearch.sweetpacks.com?src=6&q={searchTerms}&barid=&&st=23" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2e32cfe5-df92-4ae5-b0be-609ed0df74a6} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2e32cfe5-df92-4ae5-b0be-609ed0df74a6} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{71c1d63a-c944-428a-a5bd-ba513190e5d2} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{71c1d63a-c944-428a-a5bd-ba513190e5d2} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{c547c6c2-561b-4169-a2a5-20ba771ca93b} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{c547c6c2-561b-4169-a2a5-20ba771ca93b} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847} deleted successfully HKEY_USERS\S-1-5-21-391721705-2454154653-1063795786-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{2e32cfe5-df92-4ae5-b0be-609ed0df74a6} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2e32cfe5-df92-4ae5-b0be-609ed0df74a6} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{71c1d63a-c944-428a-a5bd-ba513190e5d2} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{71c1d63a-c944-428a-a5bd-ba513190e5d2} deleted successfully HKEY_CLASSES_ROOT\CLSID\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{c547c6c2-561b-4169-a2a5-20ba771ca93b} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c547c6c2-561b-4169-a2a5-20ba771ca93b} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{82E1477C-B154-48D3-9891-33D83C26BCD3} deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\4zffxtbr@VideoDownloadConverter_4z.com deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\39ffxtbr@MapsGalaxy_39.com deleted successfully ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\eooncjejnppfjjklapaamhcdmjbilmde deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ndkhncnongaclekkbelchmeafffimifj deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1 deleted successfully HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\783608352.portal.qtrax.com deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WNLT deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1 deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MapsGalaxy_39bar Uninstall deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater deleted successfully ==== HijackThis Entries ====================== R3 - URLSearchHook: (no name) - {26842a09-ffa8-4e2c-ae12-0c80f01c3295} - C:\Program Files (x86)\MapsGalaxy_39\bar\1.bin\39SrcAs.dll (file missing) F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: Linkey - {4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} - C:\PROGRA~2\Linkey\IEEXTE~1\iedll.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll O2 - BHO: Aanmeldhulp voor Microsoft-account - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O2 - BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O3 - Toolbar: SiteFinder - {CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D} - C:\Program Files (x86)\SiteFinder\SiteFinder.dll O4 - HKLM\..\Run: [MobileBroadband] C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui O4 - HKLM\..\Run: [ApnTBMon] "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [DBAgent] "C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe" /WinStart O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [Optimizer Pro] C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe O4 - HKCU\..\Run: [NTRedirect] C:\Windows\SysWOW64\rundll32.exe "C:\Users\Frans\AppData\Roaming\BabSolution\Shared\enhancedNT.dll",Run O4 - HKCU\..\Run: [Driver Pro] C:\Program Files (x86)\Driver Pro\DPLauncher.exe O4 - HKCU\..\Run: [Uploader] C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [Drivers Manager] C:\Program Files (x86)\Drivers Manager\DMLauncher.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - Startup: Belgacom Cloud.lnk = Frans\AppData\Local\F-Secure\Belgacom Cloud\Application\Belgacom Cloud.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Afbeelding verzenden naar &Bluetooth-apparaat... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Pagina verzenden naar &Bluetooth-apparaat... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing) O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing) O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Site Finder - {CCC7B152-1D8C-11E3-B2AD-F3EF3D58318D} - C:\Program Files (x86)\SiteFinder\SiteFinder.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://lynxevent.webex.com/client/WBXclient-T28L10NSP10EP1-16277/nbr/ieatgpc1.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{B337F22C-A63B-4591-8DFE-F72BA2197A2E}: NameServer = 81.169.60.107 81.169.60.107 O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing) O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HyperW7 Service (HyperW7Svc) - Lenovo Group Limited - C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe O23 - Service: Lenovo Auto Scroll (Lenovo.VIRTSCRLSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: lxcz_device - - C:\Windows\system32\lxczcoms.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe O23 - Service: Cisco EnergyWise Enabler (PwmEWSvc) - Lenovo Group Limited - C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe O23 - Service: Seagate Dashboard Services - Seagate Technology LLC - C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe O23 - Service: Seagate MobileBackup Service - Seagate Technology LLC - C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\System Update\SUService.exe O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Unknown owner - C:\Windows\System32\TPHDEXLG64.exe (file missing) O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: Vodafone Mobile Broadband-service (VmbService) - Vodafone - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Frans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Frans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QURKMGV3 will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\Frans\AppData\Local\Mozilla\Firefox\Profiles\yzanzf9u.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Frans\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=1769 folders=411 397923854 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Frans\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Frans\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\windows\SysNative\ljkb\msvcr100.dll" deleted "C:\Windows\Syswow64\jmdp\msvcr100.dll" not found "C:\windows\SysNative\dmwu.exesearch" deleted "C:\PROGRA~2\SaveSense" not found "C:\PROGRA~2\SaveSense" not found "C:\windows\SysNative\ljkb" deleted "C:\Windows\Syswow64\jmdp" not found "C:\Users\Frans\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QURKMGV3" not found ==== EOF on zo 08/06/2014 at 20:44:28,89 ======================