Zoek.exe v5.0.0.0 Updated 16-07-2014 Tool run by Deckx on do 17/07/2014 at 0:09:42,18. Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Deckx\Downloads\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 17/07/2014 0:11:12 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\HulaToo deleted successfully C:\PROGRA~2\suaave neut deleted successfully C:\PROGRA~3\Oracle deleted successfully C:\Users\Deckx\AppData\Roaming\Awesomium deleted successfully C:\Users\Deckx\AppData\Local\Adobe deleted successfully C:\Users\Deckx\AppData\Local\genienext deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util HulaToo deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util HulaToo deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Util HulaToo deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Util HulaToo deleted successfully ==== FireFox Fix ====================== ProfilePath: C:\Users\Deckx\AppData\Roaming\Mozilla\Firefox\Profiles\r91awc6l.default ---- Lines webssearch removed from prefs.js ---- user_pref("browser.search.defaultenginename", "webssearches"); ---- Lines browser.startup.page removed from prefs.js ---- user_pref("browser.startup.page", 1); ---- FireFox user.js and prefs.js backups ---- user_20141707_0018_.backup prefs_20141707_0018_.backup ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "mobilegeni daemon"=- ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\HulaToo not found C:\Program Files (x86)\Mobogenie deleted C:\Program Files\Enigma Software Group deleted C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP deleted C:\fc47e4bc2062aa37ba734b26f7 deleted C:\Users\Deckx\daemonprocess.txt deleted C:\Users\Deckx\.android deleted C:\PROGRA~3\InstallMate deleted C:\PROGRA~3\Package Cache deleted C:\Users\Deckx\AppData\Local\Mobogenie deleted C:\Users\Deckx\AppData\Local\cache deleted C:\Users\Deckx\Searches deleted C:\Windows\wininit.ini deleted C:\Windows\Syswow64\SearchProtect deleted C:\Windows\SysWow64\AI_RecycleBin deleted C:\Users\Deckx\Documents\Mobogenie deleted "C:\Windows\Installer\4832db.msi" deleted "C:\PROGRA~3\f40135156fb79f2c\{4820778D-AB0D-6D18-C316-52A6A0E1D507}" deleted "C:\PROGRA~3\f40135156fb79f2c\{4820778D-AB0D-6D18-C316-52A6A0E1D507}.old" deleted "C:\PROGRA~3\f40135156fb79f2c\{7DD5E91C-3864-77EC-7635-D14910C2A03E}" deleted "C:\PROGRA~3\f40135156fb79f2c\{7DD5E91C-3864-77EC-7635-D14910C2A03E}.old" deleted "C:\PROGRA~3\f40135156fb79f2c\{993EA8F6-6E55-7E4E-39DE-5796E3226DB9}" deleted "C:\PROGRA~3\f40135156fb79f2c\{993EA8F6-6E55-7E4E-39DE-5796E3226DB9}.old" deleted "C:\PROGRA~3\f40135156fb79f2c\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}" deleted "C:\PROGRA~3\f40135156fb79f2c" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Deckx\AppData\Local\Temp ==== 2014-07-16 11:14:49 C0A13B34E7D3276873A005291F263A5E 352992 ----a-w- C:\Users\Deckx\AppData\Local\Temp\SnapChatPC__6822_il330.exe 2014-07-15 10:27:28 DFB2CB16BA7605CF30F6DF2DA72B9831 864768 ----a-w- C:\Users\Deckx\AppData\Local\Temp\teamspeak_temp_0\platforms\qwindows.dll 2014-07-15 10:27:28 B0DE009E8EFD6E21BC0E73E356084590 4602880 ----a-w- C:\Users\Deckx\AppData\Local\Temp\teamspeak_temp_0\Qt5Core.dll 2014-07-15 10:27:28 90C6F4272AE86C02F9D2371F2BAAC2E9 685032 ----a-w- C:\Users\Deckx\AppData\Local\Temp\teamspeak_temp_0\update.exe 2014-07-15 10:27:28 601212B1136BA53229A5BBCC9F346DF0 4380160 ----a-w- C:\Users\Deckx\AppData\Local\Temp\teamspeak_temp_0\Qt5Widgets.dll 2014-07-15 10:27:28 4BA25D2CBE1587A841DCFB8C8C4A6EA6 875472 ----a-w- C:\Users\Deckx\AppData\Local\Temp\teamspeak_temp_0\msvcr110.dll 2014-07-15 10:27:28 3E29914113EC4B968BA5EB1F6D194A0A 535008 ----a-w- C:\Users\Deckx\AppData\Local\Temp\teamspeak_temp_0\msvcp110.dll 2014-07-15 10:27:28 2DF561B4293785267C40134EF3726E1E 25600 ----a-w- C:\Users\Deckx\AppData\Local\Temp\teamspeak_temp_0\imageformats\qgif.dll 2014-07-15 10:27:28 229ED86EF4F14979CE2DC365F2243AFB 830976 ----a-w- C:\Users\Deckx\AppData\Local\Temp\teamspeak_temp_0\Qt5Network.dll 2014-07-15 10:27:28 0EBF01A0DF03086077155C5C63B09753 242688 ----a-w- C:\Users\Deckx\AppData\Local\Temp\teamspeak_temp_0\imageformats\qjpeg.dll 2014-07-15 10:27:28 0BD368B2C20613D00FCE0D06CD175325 2860032 ----a-w- C:\Users\Deckx\AppData\Local\Temp\teamspeak_temp_0\Qt5Gui.dll ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== ====== C:\Windows\Sysnative\drivers ===== 2014-07-09 12:29:25 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\Sysnative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2014-06-21 12:00:07 8E98D21EE06192492A5671A6144D092F 33240 ----a-w- C:\Windows\Sysnative\drivers\GEARAspiWDM.sys ====== C:\Windows\Tasks ====== 2014-07-16 18:33:18 -------- d-----w- C:\Windows\Sysnative\Tasks\Safer-Networking 2014-07-16 17:15:26 8CDD5FD292359A1D29AEF0947F004EA4 3150 ----a-w- C:\Windows\Sysnative\Tasks\{B52EB8D7-AF49-4BE3-ABB8-004BA2C5D415} 2014-06-21 11:59:17 -------- d-----w- C:\Windows\Sysnative\Tasks\Apple ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-07-16 18:32:19 -------- d-----w- C:\Program Files\trend micro 2014-06-21 11:59:53 -------- d-----w- C:\Program Files\iPod 2014-06-21 11:59:52 -------- d-----w- C:\Program Files\iTunes 2014-06-21 11:59:09 -------- d-----w- C:\Program Files\Common Files\Apple 2014-06-21 11:58:58 -------- d-----w- C:\Program Files\Bonjour ======= C:\PROGRA~2 ===== 2014-07-05 19:43:22 -------- d-----w- C:\PROGRA~2\Mozilla Maintenance Service 2014-06-21 11:59:52 -------- d-----w- C:\PROGRA~2\iTunes 2014-06-21 11:59:16 -------- d-----w- C:\PROGRA~2\Apple Software Update 2014-06-21 11:58:58 -------- d-----w- C:\PROGRA~2\Bonjour 2014-06-21 11:58:41 -------- d-----w- C:\PROGRA~2\COMMON~1\Apple ======= C: ===== 2014-07-16 17:52:49 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\autoexec.bat ====== C:\Users\Deckx\AppData\Roaming ====== 2014-07-05 19:43:30 -------- d-----w- C:\Users\Deckx\AppData\Roaming\Mozilla 2014-07-05 19:43:30 -------- d-----w- C:\Users\Deckx\AppData\Local\Mozilla 2014-06-21 12:00:19 -------- d-----w- C:\Users\Deckx\AppData\Roaming\Apple Computer 2014-06-21 12:00:19 -------- d-----w- C:\Users\Deckx\AppData\Local\Apple Computer 2014-06-21 11:59:17 -------- d-----w- C:\Users\Deckx\AppData\Local\Apple 2014-06-21 11:59:13 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\Apple Computer ====== C:\Users\Deckx ====== 2014-07-16 18:31:36 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Deckx\Downloads\RSITx64.exe 2014-07-16 17:51:20 E2204230A1FC502A780E96A3E7F3C8EF 728960 ----a-w- C:\Users\Deckx\Downloads\SpyHunter-Installer.exe 2014-07-16 17:17:14 7B9D4F33E329C1D41B234B069698B057 632 --sha-r- C:\Users\Deckx\ntuser.pol 2014-07-16 11:14:41 C0A13B34E7D3276873A005291F263A5E 352992 ----a-w- C:\Users\Deckx\Downloads\SnapChatPC__6822_il330.exe 2014-07-10 11:07:37 D07800D4245C6647414A2D0491005746 895120 ----a-w- C:\Users\Deckx\Downloads\ChromeSetup (1).exe 2014-07-09 14:21:46 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Capitalism II 2014-07-05 19:43:23 -------- d-----w- C:\ProgramData\Mozilla 2014-07-05 19:42:57 351D83CBC02C48CA0AF90AFE233FCF79 284224 ----a-w- C:\Users\Deckx\Downloads\Firefox Setup Stub 30.0.exe 2014-07-03 09:49:23 91B4C2EC7BB52EBC80DC76A1F3B9DFB4 23978024 ----a-w- C:\Users\Deckx\Downloads\PS2_setup (1).exe 2014-06-21 12:00:18 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-06-21 11:59:52 -------- d-----w- C:\ProgramData\Apple Computer 2014-06-21 11:59:52 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-06-21 11:58:41 -------- d-----w- C:\ProgramData\Apple ====== C: exe-files == 2014-07-16 18:32:19 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Deckx.exe 2014-07-16 18:31:36 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Deckx\Downloads\RSITx64.exe 2014-07-16 17:51:20 E2204230A1FC502A780E96A3E7F3C8EF 728960 ----a-w- C:\Users\Deckx\Downloads\SpyHunter-Installer.exe 2014-07-16 11:14:49 C0A13B34E7D3276873A005291F263A5E 352992 ----a-w- C:\Users\Deckx\AppData\Local\Temp\SnapChatPC__6822_il330.exe 2014-07-16 11:14:41 C0A13B34E7D3276873A005291F263A5E 352992 ----a-w- C:\Users\Deckx\Downloads\SnapChatPC__6822_il330.exe 2014-07-15 10:27:28 90C6F4272AE86C02F9D2371F2BAAC2E9 685032 ----a-w- C:\Users\Deckx\AppData\Local\Temp\teamspeak_temp_0\update.exe 2014-07-10 11:07:54 EDAC53E2964C7ACE868208C3B6C5C8F1 39078480 ----a-w- C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\35.0.1916.153\35.0.1916.153_chrome_installer.exe 2014-07-10 11:07:46 D07800D4245C6647414A2D0491005746 895120 ----a-w- C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleUpdateSetup.exe 2014-07-10 11:07:46 AC6998D92A311E7CF0B4DAEC3566F444 51080 ----atw- C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleUpdateBroker.exe 2014-07-10 11:07:46 AA0E4F73727BFC8BA404884B1C1DB719 285064 ----atw- C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe 2014-07-10 11:07:46 956672375AF066D958E4D07F5ABAFC1A 51080 ----atw- C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleUpdateOnDemand.exe 2014-07-10 11:07:46 80E350E0AA963B2125896B13E60A4D68 114568 ----atw- C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleUpdateComRegisterShell64.exe 2014-07-10 11:07:46 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 2014-07-10 11:07:46 506708142BC63DABA64F2D3AD1DCD5BF 116648 ----atw- C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleUpdate.exe 2014-07-10 11:07:46 397D14958D6C9C2B365469A857B2AC4E 230792 ----atw- C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe 2014-07-10 11:07:37 D07800D4245C6647414A2D0491005746 895120 ----a-w- C:\Users\Deckx\Downloads\ChromeSetup (1).exe === C: other files == 2014-07-16 17:52:49 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\autoexec.bat ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-1818497608-2437012134-3316047982-1000\Software\Microsoft\Windows\CurrentVersion\Run] "RGSC"="C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent" "Akamai NetSession Interface"="C:\Users\Deckx\AppData\Local\Akamai\netsession_win.exe" "DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun" "Facebook Update"="C:\Users\Deckx\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RUSB3MON"="C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe" "Super-Charger"="C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe" "Aeria Ignite"="C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe silent" "GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui" "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun" "vmware-tray.exe"="C:\Program Files (x86)\VMware\VMware Player\vmware-tray.exe" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "RGSC"="C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent" "Akamai NetSession Interface"="C:\Users\Deckx\AppData\Local\Akamai\netsession_win.exe" "DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun" "Facebook Update"="C:\Users\Deckx\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skype" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Skype\\Phone\\Skype.exe\" /minimized /regrun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AMD External Events Utility] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\AMD FUEL Service] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdate] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\gupdatem] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\MSI_SuperCharger] ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [09/07/2014 17:16] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1818497608-2437012134-3316047982-1000Core.job --a------ C:\Users\Deckx\AppData\Local\Facebook\Update\FacebookUpdate.exe [22/03/2014 15:52] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1818497608-2437012134-3316047982-1000UA.job --a------ C:\Users\Deckx\AppData\Local\Facebook\Update\FacebookUpdate.exe [22/03/2014 15:52] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [10/07/2014 13:07] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [10/07/2014 13:07] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-1818497608-2437012134-3316047982-1000Core" [C:\Users\Deckx\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-1818497608-2437012134-3316047982-1000UA" [C:\Users\Deckx\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{2745A277-F01E-43C0-84FC-916E13C1CEE8}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [28/03/2014 16:35] ==== Firefox Extensions ====================== AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Deckx\AppData\Roaming\Mozilla\Firefox\Profiles\r91awc6l.default 4390CCD3790F8D9C427C0C29590C62D7 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll - Shockwave Flash 5B0F6A8F086D3220272919A3023EF180 - C:\Users\Deckx\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player FF0D6F82A0EC13952E83B9439100E45D - C:\Users\Deckx\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions bmiabdepfhhiieiipmeecdmeljggmfee - No path found[] gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[28/03/2014 16:35] lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[11/04/2014 19:46] save on - Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag DuckDuckGo for Chrome - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao save on - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag YoutubeAdblocker - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh DuckDuckGo for Chrome - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao save on - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag YoutubeAdblocker - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh savee net - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcdlhjekncnmlgbbgjodnffdcjfocjme DuckDuckGo for Chrome - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao save on - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag YoutubeAdblocker - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh DuckDuckGo for Chrome - Administrator\AppData\Local\Torch\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao save on - Administrator\AppData\Local\Torch\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - Administrator\AppData\Local\Torch\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - Administrator\AppData\Local\Torch\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag YoutubeAdblocker - Administrator\AppData\Local\Torch\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh save on - Deckx\AppData\Local\Chromatic Browser\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - Deckx\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - Deckx\AppData\Local\Chromatic Browser\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag DuckDuckGo for Chrome - Deckx\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao save on - Deckx\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - Deckx\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - Deckx\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag YoutubeAdblocker - Deckx\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh Google Voice Search Hotword (Beta) - Deckx\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn Last updated at time on date - Deckx\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb save on - Deckx\AppData\Local\Google\Chrome\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo avast Online Security - Deckx\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki Shortcut Manager - Deckx\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgjjeipcdnnjhgodgjpfkffcejoljijf Google Wallet - Deckx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Battlefield Play4Free - Deckx\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh DuckDuckGo for Chrome - Deckx\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao save on - Deckx\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - Deckx\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - Deckx\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag YoutubeAdblocker - Deckx\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh DuckDuckGo for Chrome - Deckx\AppData\Local\Torch\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao save on - Deckx\AppData\Local\Torch\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - Deckx\AppData\Local\Torch\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - Deckx\AppData\Local\Torch\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag YoutubeAdblocker - Deckx\AppData\Local\Torch\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh save on - Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag DuckDuckGo for Chrome - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao save on - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag YoutubeAdblocker - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh DuckDuckGo for Chrome - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao save on - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag YoutubeAdblocker - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh DuckDuckGo for Chrome - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao save on - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag YoutubeAdblocker - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh DuckDuckGo for Chrome - Guest\AppData\Local\Torch\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao save on - Guest\AppData\Local\Torch\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - Guest\AppData\Local\Torch\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - Guest\AppData\Local\Torch\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag YoutubeAdblocker - Guest\AppData\Local\Torch\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh save on - HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag DuckDuckGo for Chrome - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao save on - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag YoutubeAdblocker - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh DuckDuckGo for Chrome - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao save on - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag YoutubeAdblocker - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh DuckDuckGo for Chrome - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao save on - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag YoutubeAdblocker - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh DuckDuckGo for Chrome - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao save on - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo suaave neut - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm save on - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag YoutubeAdblocker - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh ==== Chrome Fix ====================== C:\Users\Deckx\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage deleted successfully C:\Users\Deckx\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully C:\Users\Deckx\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_need-for-speed-most-wanted-demo.nl.softonic.com_0.localstorage deleted successfully C:\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\Deckx\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\Deckx\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\Deckx\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\Deckx\AppData\Local\Torch\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\ekmddlopnbabmihhndjnhcbmoabdagfm deleted successfully C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh deleted successfully C:\Users\Deckx\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh deleted successfully C:\Users\Deckx\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh deleted successfully C:\Users\Deckx\AppData\Local\Torch\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh deleted successfully C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh deleted successfully C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh deleted successfully C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh deleted successfully C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jaomepkfbjihioicjdceifegjmjooidh deleted successfully C:\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\Deckx\AppData\Local\Chromatic Browser\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\Deckx\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\Deckx\AppData\Local\Google\Chrome\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\Deckx\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\Deckx\AppData\Local\Torch\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\deeagmmhjghdbnaeobebfalamhlfjcpo deleted successfully C:\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\Deckx\AppData\Local\Chromatic Browser\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\Deckx\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\Deckx\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\Deckx\AppData\Local\Torch\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\fdfkacjbghgleepmdodcklneflhcdeag deleted successfully C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao deleted successfully C:\Users\Deckx\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao deleted successfully C:\Users\Deckx\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao deleted successfully C:\Users\Deckx\AppData\Local\Torch\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao deleted successfully C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao deleted successfully C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao deleted successfully C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao deleted successfully C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pcdlhjekncnmlgbbgjodnffdcjfocjme deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://istart.webssearches.com/web/?type=ds&ts=1405509366&from=amt&uid=ST1000DM003-1CH162_S1DF8GM7XXXXS1DF8GM7&q={searchTerms}" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Search Page"="http://istart.webssearches.com/web/?type=ds&ts=1405509366&from=amt&uid=ST1000DM003-1CH162_S1DF8GM7XXXXS1DF8GM7&q={searchTerms}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{33BB0A4E-99AF-4226-BDF6-49120163DE86}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" ==== shortcuts on Users Desktops ====================== C:\Users\Deckx\Desktop\Alliance of Valiant Arms.lnk - C:\AeriaGames\AVA\aeria_launcher.exe av C:\Users\Deckx\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://istart.webssearches.com/?type=sc&ts=1405509366&from=amt&uid=ST1000DM003-1CH162_S1DF8GM7XXXXS1DF8GM7 C:\Users\Deckx\Desktop\PlanetSide 2.lnk - C:\Users\Public\Sony Online Entertainment\Installed Games\PlanetSide 2\LaunchPad.exe C:\Users\Deckx\Desktop\Shaiya Phoenix.lnk - C:\AeriaGames\ShaiyaPhoenix\aeria_launcher.exe sypx C:\Users\Deckx\Desktop\Shaiya.lnk - C:\AeriaGames\Shaiya\aeria_launcher.exe sy ==== shortcuts on All Users Desktop ====================== C:\Users\Public\Desktop\Aeria Ignite.lnk - C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe C:\Users\Public\Desktop\avast Free Antivirus.lnk - C:\Users\Public\Desktop\Barbarian Invasion.lnk - C:\Program Files (x86)\The Creative Assembly\Rome - Total War\RomeTW-BI.exe C:\Users\Public\Desktop\CADdy++ - SEE Electrical schoolversie.lnk - C:\Program Files (x86)\CADdy++ - SEE Electrical School\CAEManager.exe C:\Users\Public\Desktop\Capitalism II.lnk - C:\Capitalism II\cap2.exe C:\Users\Public\Desktop\DAEMON Tools Lite.lnk - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe C:\Users\Public\Desktop\De Sims 2.lnk - C:\Program Files (x86)\EA Games\De Sims 2\TSBin\Sims2.exe C:\Users\Public\Desktop\De Sims™ 3.lnk - C:\Users\Public\Desktop\GOM Player.lnk - C:\Program Files (x86)\GRETECH\GomPlayer\GOM.EXE C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://istart.webssearches.com/?type=sc&ts=1405509366&from=amt&uid=ST1000DM003-1CH162_S1DF8GM7XXXXS1DF8GM7 C:\Users\Public\Desktop\GTA San Andreas.lnk - C:\Program Files (x86)\Rockstar Games\GTA San Andreas\gta_sa.exe C:\Users\Public\Desktop\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe C:\Users\Public\Desktop\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://istart.webssearches.com/?type=sc&ts=1405509366&from=amt&uid=ST1000DM003-1CH162_S1DF8GM7XXXXS1DF8GM7 C:\Users\Public\Desktop\Need for Speed Most Wanted.lnk - C:\Program Files (x86)\EA Games\Need for Speed Most Wanted\NFS13.exe C:\Users\Public\Desktop\Need for Speed™ Undercover.lnk - C:\Users\Public\Desktop\Rome - Total War.lnk - C:\Program Files (x86)\The Creative Assembly\Rome - Total War\RomeTW.exe C:\Users\Public\Desktop\Skype.lnk - C:\Windows\Installer\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}\SkypeIcon.exe C:\Users\Public\Desktop\Steam.lnk - C:\Program Files (x86)\Steam\Steam.exe C:\Users\Public\Desktop\Teach2000.lnk - C:\Program Files (x86)\Teach2000\Teach2000.exe C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk - C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe C:\Users\Public\Desktop\The Walking Dead.lnk - C:\Program Files (x86)\Telltale Games\The Walking Dead\GameData\WalkingDead101.exe C:\Users\Public\Desktop\VMware Workstation.lnk - C:\Program Files (x86)\VMware\VMware Player\vmware.exe C:\Users\Public\Desktop\Zoo Tycoon.lnk - C:\Program Files (x86)\Microsoft Games\Zoo Tycoon\zoo.exe ==== shortcuts in Users Start Menu ====================== C:\Users\Deckx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk - C:\Program Files\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1405509366&from=amt&uid=ST1000DM003-1CH162_S1DF8GM7XXXXS1DF8GM7 C:\Users\Deckx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1405509366&from=amt&uid=ST1000DM003-1CH162_S1DF8GM7XXXXS1DF8GM7 C:\Users\Deckx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlanetSide 2.lnk - C:\Users\Public\Sony Online Entertainment\Installed Games\PlanetSide 2\LaunchPad.exe C:\Users\Deckx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1405509366&from=amt&uid=ST1000DM003-1CH162_S1DF8GM7XXXXS1DF8GM7 ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk - C:\Windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://istart.webssearches.com/?type=sc&ts=1405509366&from=amt&uid=ST1000DM003-1CH162_S1DF8GM7XXXXS1DF8GM7 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Capitalism II\Capitalism II.lnk - C:\Capitalism II\cap2.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Capitalism II\Register Capitalism II.lnk - C:\Capitalism II\Ubi1.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Capitalism II\ubi.com - Capitalism II web site.lnk - C:\Capitalism II\cap2home.url C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Capitalism II\Uninstall Capitalism II.lnk - C:\Windows\system32\RunDll32.exe C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{EF581945-BBE9-11D5-A7FE-50275FC10000}\setup.exe" -uninst -f Setup.ilg C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\Info iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.Resources\nl.lproj\About iTunes.rtf C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe ==== shortcuts in Quick Launch ====================== C:\Users\Deckx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk - C:\Program Files (x86)\GRETECH\GomPlayer\GOM.EXE C:\Users\Deckx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://istart.webssearches.com/?type=sc&ts=1405509366&from=amt&uid=ST1000DM003-1CH162_S1DF8GM7XXXXS1DF8GM7 C:\Users\Deckx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://istart.webssearches.com/?type=sc&ts=1405509366&from=amt&uid=ST1000DM003-1CH162_S1DF8GM7XXXXS1DF8GM7 C:\Users\Deckx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Deckx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\VMware Workstation.lnk - C:\Program Files (x86)\VMware\VMware Player\vmware.exe C:\Users\Deckx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Deckx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\Windows\system32\control.exe C:\Users\Deckx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://istart.webssearches.com/?type=sc&ts=1405509366&from=amt&uid=ST1000DM003-1CH162_S1DF8GM7XXXXS1DF8GM7 C:\Users\Deckx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\TeamSpeak 3 Client.lnk - C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe C:\Users\Deckx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\Windows\explorer.exe C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\VMware Workstation.lnk - C:\Program Files (x86)\VMware\VMware Player\vmware.exe C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\VMware Workstation.lnk - C:\Program Files (x86)\VMware\VMware Player\vmware.exe C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - ==== shortcuts After Repair ====================== C:\Users\Deckx\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Public\Desktop\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Users\Deckx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Deckx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\Deckx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Users\Deckx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Deckx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\Deckx\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F60730A4A66673047777F5728467D401 deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\1ecf05df-e0c6-45c6-a111-55ea3ec7955e deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\bmiabdepfhhiieiipmeecdmeljggmfee deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\bmiabdepfhhiieiipmeecdmeljggmfee deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401 deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Users\Deckx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Deckx\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Deckx\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Deckx\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\Deckx\AppData\Local\Mozilla\Firefox\Profiles\r91awc6l.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Deckx\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=921 folders=256 58284752 bytes) ==== Empty Temp Folders ====================== C:\Users\Deckx\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot