Zoek.exe v5.0.0.0 Updated 19-07-2014 Tool run by klajoelja on di 22-07-2014 at 11:22:40,81. Microsoft Windows 7 Home Premium 6.1.7600 x64 Running in: Safe Mode NETWORK Internet Access Detected Launched: C:\Users\klajoelja\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== ==== Empty Folders Check ====================== C:\PROGRA~2\MSXML 4.0 deleted successfully C:\Program Files\Symantec deleted successfully C:\PROGRA~3\Babylon deleted successfully C:\PROGRA~3\Shared Space deleted successfully C:\Users\klajoelja\AppData\Roaming\TP deleted successfully C:\Users\klajoelja\AppData\Local\PackageAware deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4a99-B4B6-146BF802613B} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4a99-B4B6-146BF802613B} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C45EC9F0-8333-465D-9728-074BD41985C9} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C45EC9F0-8333-465D-9728-074BD41985C9} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49dd-99D7-DC866BE87DBC} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49dd-99D7-DC866BE87DBC} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Internet Explorer\SearchScopes\{B2EE6AEE-1539-4EFD-9AA1-66CD0FF156E4} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Internet Explorer\SearchScopes\{B62C21DF-4BBA-439E-9BD5-2704ECB31755} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_CLASSES_ROOT\CLSID\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} deleted successfully HKEY_CLASSES_ROOT\CLSID\{C45EC9F0-8333-465D-9728-074BD41985C9} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{C45EC9F0-8333-465D-9728-074BD41985C9} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C45EC9F0-8333-465D-9728-074BD41985C9} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C45EC9F0-8333-465D-9728-074BD41985C9} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{F1C81E40-2485-4DB6-8C9D-04BD596B281E} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F1C81E40-2485-4DB6-8C9D-04BD596B281E} deleted successfully HKEY_CLASSES_ROOT\CLSID\{FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB16E5C3-A9E2-47A2-8EFC-319E775E62CC} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{828DC97A-2277-4E10-92A9-4907FA0922A9} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2F5C139F-79BD-4C84-A95A-E7140525BC55} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{2F5C139F-79BD-4C84-A95A-E7140525BC55} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{98889811-442D-49dd-99D7-DC866BE87DBC} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{828DC97A-2277-4E10-92A9-4907FA0922A9} deleted successfully ==== Running Processes ====================== C:\Windows\SysWOW64\MPK\mpk.exe C:\Users\klajoelja\Desktop\zoek.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BackupStack deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BackupStack deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wpm deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Wpm deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Wpm deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IePluginService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\IePluginService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\IePluginService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IePluginServices deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\IePluginServices deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\IePluginServices deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\wajamupdater deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wajamupdater deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\wajamupdater deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\wajamupdater deleted successfully ==== FireFox Fix ====================== ProfilePath: C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default user.js not found ---- Lines buenosearch removed from prefs.js ---- user_pref("extensions.buenosearch.admin", false); user_pref("extensions.buenosearch.aflt", "babsst"); user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}"); user_pref("extensions.buenosearch.autoRvrt", "false"); user_pref("extensions.buenosearch.dfltLng", "en"); user_pref("extensions.buenosearch.excTlbr", false); user_pref("extensions.buenosearch.ffxUnstlRst", true); user_pref("extensions.buenosearch.id", "0218bb30000000000000c446197c3cf1"); user_pref("extensions.buenosearch.instlDay", "16207"); user_pref("extensions.buenosearch.instlRef", "sst"); user_pref("extensions.buenosearch.newTab", false); user_pref("extensions.buenosearch.prdct", "buenosearch"); user_pref("extensions.buenosearch.prtnrId", "buenosearch"); user_pref("extensions.buenosearch.rvrt", "false"); user_pref("extensions.buenosearch.smplGrp", "none"); user_pref("extensions.buenosearch.tb_url", "http://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=0218C446197C3CF1&affID=127873&tsp=5250"); user_pref("extensions.buenosearch.tlbrId", "base"); user_pref("extensions.buenosearch.tlbrSrchUrl", "http://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=0218C446197C3CF1&affID=127873&tsp=525 user_pref("extensions.buenosearch.vrsn", "1.8.28.7"); user_pref("extensions.buenosearch.vrsnTs", "1.8.28.719:11:39"); user_pref("extensions.buenosearch.vrsni", "1.8.28.7"); ---- Lines buenosearch modified from prefs.js ---- user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{BBDA0591-3099-440a-AA10-41764D9DB4DB}\":{\"descriptor\":\"C:\\\\ ---- FireFox user.js and prefs.js backups ---- prefs_22-07-2014_1136_.backup ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command] @="C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command] @="C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command] @="C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe" ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C45EC9F0-8333-465D-9728-074BD41985C9}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB16E5C3-A9E2-47A2-8EFC-319E775E62CC}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C45EC9F0-8333-465D-9728-074BD41985C9}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F1C81E40-2485-4DB6-8C9D-04BD596B281E}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB16E5C3-A9E2-47A2-8EFC-319E775E62CC}] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Softonic for Windows"=- [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] "PrivDogService"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\BabylonToolbar not found C:\ProgramData\Shared Space not found "C:\$Recycle.Bin\S-1-5-18\$ebf3b266f1ec9308fc79dd240b818a0f" not found C:\Program Files (x86)\DVDVideoSoftTB deleted C:\Program Files (x86)\Vuze_Remote deleted C:\Program Files (x86)\Speed Test 127 deleted C:\Program Files (x86)\SupTab deleted C:\Program Files (x86)\Wajam deleted C:\Program Files (x86)\Free Games 111 deleted C:\Program Files (x86)\buenosearch LTD deleted C:\Program Files (x86)\AdTrustMedia deleted C:\Users\klajoelja\AppData\Local\Softonic deleted C:\Program Files (x86)\MyPC Backup deleted C:\Users\klajoelja\AppData\Roaming\DVDVideoSoftIEHelpers deleted C:\Program Files (x86)\PC Performer deleted C:\Program Files (x86)\Mozilla Firefox\extensions\{6AA54174-C9E8-4B07-95A0-0FBC19CBE64C} deleted C:\Program Files (x86)\Mozilla Firefox\extensions\{129b29a3-f554-444b-aa12-8ead59836cc8} deleted C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\faststartff@gmail.com deleted C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\ffxtlbr@buenosearch.com deleted C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\freegames4357@BestOffers deleted C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\quick_start@gmail.com deleted C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\shortcutff@gmail.com deleted C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\speedtest4354@BestOffers deleted C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} deleted C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} deleted C:\Program Files\AdTrustMedia deleted C:\ProgramData\Adtrustmedia deleted C:\Users\klajoelja\AppData\Roaming\sweet-page deleted C:\Users\klajoelja\AppData\Roaming\SupTab deleted C:\Users\klajoelja\AppData\Roaming\buenosearch LTD deleted C:\Users\klajoelja\AppData\Roaming\BabSolution deleted C:\Users\klajoelja\AppData\Roaming\337Games deleted C:\Program Files (x86)\PricePeep deleted C:\PROGRA~2\DealPly deleted C:\PROGRA~2\FoxTabPDFConverter deleted C:\PROGRA~2\SopCast deleted C:\PROGRA~2\COMMON~1\DVDVideoSoft\TB deleted C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted C:\PROGRA~2\BasicScan deleted C:\PROGRA~2\iLivid deleted C:\PROGRA~2\Ask.com deleted C:\PROGRA~2\Conduit deleted C:\PROGRA~2\COMMON~1\Spigot deleted C:\found.000 deleted C:\Users\klajoelja\AppData\Roaming\skype.dat deleted C:\Users\klajoelja\AppData\Roaming\Babylon deleted C:\Users\klajoelja\AppData\Roaming\PerformerSoft deleted C:\PROGRA~3\Ask deleted C:\PROGRA~3\IePluginService deleted C:\PROGRA~3\IePluginServices deleted C:\PROGRA~3\boost_interprocess deleted C:\PROGRA~3\WPM deleted C:\PROGRA~3\Tarma Installer deleted C:\Users\klajoelja\AppData\Local\Ilivid Player deleted C:\Users\klajoelja\AppData\Local\RavenBleuSA deleted C:\Users\klajoelja\AppData\Local\Conduit deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Performer deleted C:\Users\klajoelja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup deleted C:\Users\klajoelja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk deleted C:\Users\klajoelja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Softonic deleted C:\Users\klajoelja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted C:\Windows\SysNative\roboot64.exe deleted C:\windows\SysNative\Tasks\PC Performer deleted C:\windows\SysNative\Tasks\PC Performer_DEFAULT deleted C:\windows\SysNative\Tasks\PC Performer_UPDATES deleted C:\Users\klajoelja\Downloads\iLividSetup.exe deleted C:\Users\klajoelja\Downloads\iLividSetupV1.exe deleted C:\Users\klajoelja\Downloads\sopcast.nl.3.4.0.zip deleted C:\Users\klajoelja\Searches deleted C:\Users\klajoelja\Downloads\SoftonicDownloader_voor_farming-simulator.exe deleted C:\Users\klajoelja\AppData\LocalLow\DVDVideoSoftTB deleted C:\Users\klajoelja\AppData\LocalLow\Vuze_Remote deleted C:\Users\klajoelja\AppData\LocalLow\Delta deleted C:\Users\klajoelja\AppData\LocalLow\Conduit deleted C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Application Updater deleted C:\Windows\tasks\PC Performer_DEFAULT.job deleted C:\Windows\tasks\PC Performer_UPDATES.job deleted C:\windows\SysNative\Tasks\EPUpdater deleted C:\user.js deleted C:\END deleted C:\Windows\SysNative\config\systemprofile\Searches deleted C:\Windows\Syswow64\TBD4547.tmp deleted C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\searchplugins\babylon.xml deleted C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\searchplugins\askcom.xml deleted C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\searchplugins\buenosearch.xml deleted C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\searchplugins\Search_Results.xml deleted C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\valueApps deleted C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\Invalidprefs.js deleted C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\CT2269050 deleted C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\CT2504091 deleted C:\Users\klajoelja\Desktop\Continue FoxTab PDF Creator Installation.lnk deleted C:\Users\klajoelja\Desktop\Continue Zip Opener Installation.lnk deleted C:\Users\klajoelja\Desktop\Free Games.lnk deleted C:\Users\klajoelja\Desktop\Sync Folder.lnk deleted C:\Users\klajoelja\Desktop\rcpsetup_softonic_sd_new.exe deleted C:\Users\klajoelja\Desktop\rcpsetup_softonic_sd_new[1].exe deleted C:\Users\klajoelja\Desktop\Softonic.lnk deleted C:\Users\klajoelja\Desktop\MyPC Backup.lnk deleted C:\Users\klajoelja\AppData\Roaming\pack.exe deleted C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\conduitCommon deleted C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\{F0B1CEAC-7C0D-407c-B25E-623D7CBECCCB} deleted C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\smartbar deleted "C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\searchplugins\delta.xml" deleted "C:\windows\SysNative\TBD4586.tmp" deleted "C:\windows\SysNative\TBD4507.tmp" deleted "C:\Windows\Installer\198c8cb.msi" deleted "C:\ProgramData\efeb6c6e64dc5eff8f39144107293ea4_c" deleted "C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\searchplugins\delta.xml" deleted "C:\PROGRA~2\Mozilla Firefox\browser\searchplugins\delta-homes.xml" deleted "C:\$Recycle.Bin\S-1-5-21-3527801987-756735660-2910266346-1000\$ebf3b266f1ec9308fc79dd240b818a0f\@" deleted "C:\$Recycle.Bin\S-1-5-21-3527801987-756735660-2910266346-1000\$ebf3b266f1ec9308fc79dd240b818a0f\n" deleted "C:\$Recycle.Bin\S-1-5-21-3527801987-756735660-2910266346-1000\$ebf3b266f1ec9308fc79dd240b818a0f\U\00000001.@" deleted "C:\$Recycle.Bin\S-1-5-21-3527801987-756735660-2910266346-1000\$ebf3b266f1ec9308fc79dd240b818a0f\U\80000000.@" deleted "C:\$Recycle.Bin\S-1-5-21-3527801987-756735660-2910266346-1000\$ebf3b266f1ec9308fc79dd240b818a0f\U\800000cb.@" deleted "C:\$Recycle.Bin\S-1-5-21-3527801987-756735660-2910266346-1000\$ebf3b266f1ec9308fc79dd240b818a0f" deleted "C:\$Recycle.Bin\S-1-5-21-3527801987-756735660-2910266346-1000\$ebf3b266f1ec9308fc79dd240b818a0f\L" deleted "C:\$Recycle.Bin\S-1-5-21-3527801987-756735660-2910266346-1000\$ebf3b266f1ec9308fc79dd240b818a0f\U" deleted ==== Registry Search Results for "$ebf3b266f1ec9308fc79dd240b818a0f" ====================== No instances of string "$ebf3b266f1ec9308fc79dd240b818a0f" found. ==== System Specs ====================== Windows: Windows 7 Home Premium Edition (64-bit) (Build 7600) Memory (RAM): 3894 MB CPU Info: Intel(R) Core(TM) i3 CPU M 350 @ 2.27GHz CPU Speed: 2269,8 MHz Sound Card: Not detected Display Adapters: | RDP Encoder Mirror Driver Monitors: 1x; Screen Resolution: 800 X 600 - 32 bit Network: Network Present Network Adapters: Microsoft Virtual WiFi Miniport Adapter | Broadcom 4313 (802.11b/g/n) CD / DVD Drives: 1x (E: | ) E: hp CDDVDW TS-L633N Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 5 Button Wheel Mouse Present Hard Disks: C: 449,4GB | D: 16,1GB Hard Disks - Free: C: 305,8GB | D: 2,3GB Manufacturer *: Hewlett-Packard BIOS Info: AT/AT COMPATIBLE | 08/02/10 | HPQOEM - 1 Time Zone: West-Europa (standaardtijd) Motherboard *: Hewlett-Packard 143A Country: Nederland Language: NLD ==== System Specs (Software) ====================== Anti-Virus: Norton Internet Security On-access scanning disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Anti-Spyware: Norton Internet Security disabled (Outdated) Firewall: Norton Internet Security disabled Default Browser: Google Chrome 35.0.1916.153 Internet Explorer Version: 9.0.8112.16421 Mozilla Firefox version: 29.0.1 (x86 nl) Google Chrome version: 35.0.1916.153 Adobe Reader version: 11.0.07.79 Sun Java version: 1.7.0_17 (32-bit) Sun Java version: 1.7.0_07 (64-bit) Flash Player version: 13.0.0.214 Shockwave Player version: 11.5.7r609 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\KLAJOE~1\AppData\Local\Temp ==== 2014-07-20 17:21:18 69CE5E18A4CB5A349E35DC6981FFF8CE 4464640 ----a-w- C:\Users\klajoelja\AppData\Local\Temp\Lang_nl-NL.msi ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== ====== C:\Windows\Sysnative\drivers ===== 2014-07-06 12:20:36 FA847104FA5CE9881472C54F12669D77 6080 ----a-w- C:\Windows\Sysnative\drivers\sfi.dat ====== C:\Windows\Tasks ====== 2014-07-06 12:21:48 -------- d-----w- C:\Windows\Sysnative\Tasks\COMODO ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-07-21 18:54:10 -------- d-----w- C:\Program Files\trend micro 2014-07-01 16:09:36 -------- d-----w- C:\Program Files\COMODO ======= C:\PROGRA~2 ===== 2014-07-06 12:44:58 -------- d-----w- C:\PROGRA~2\COMMON~1\COMODO 2014-07-01 16:09:04 -------- d-----w- C:\PROGRA~2\Comodo ======= C: ===== ====== C:\Users\klajoelja\AppData\Roaming ====== 2014-07-16 22:37:11 -------- d-----w- C:\Windows\SysNative\config\systemprofile\AppData\Locallow\COMODO 2014-07-16 22:13:13 -------- d-----w- C:\Users\klajoelja\AppData\Local\Windows Live 2014-07-06 12:34:48 -------- d-----w- C:\Users\klajoelja\AppData\Local\AdTrustMedia 2014-07-06 12:32:39 -------- d-----w- C:\Users\klajoelja\AppData\Locallow\COMODO 2014-07-06 12:26:07 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Comodo 2014-07-01 16:09:53 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Locallow\COMODO ====== C:\Users\klajoelja ====== 2014-07-20 16:55:46 -------- d--h--w- C:\ProgramData\Common Files 2014-07-20 16:55:46 -------- d-----w- C:\ProgramData\AVG 2014-07-01 16:13:38 -------- d-----w- C:\Users\Administrator\Links 2014-07-01 16:09:20 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo 2014-07-01 16:08:55 -------- d-----w- C:\ProgramData\Comodo Downloader 2014-07-01 16:08:11 -------- d-----w- C:\ProgramData\Comodo ====== C: exe-files == 2014-07-21 18:54:10 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\klajoelja.exe 2014-07-20 16:49:38 27562984CA653EC72C5893DEEE822CF7 637864 ----a-w- C:\ProgramData\Comodo\lps4\temp\setup_clps_application_vulnerability_monitor_release-4.10.307677.9.exe 2014-07-20 16:48:57 BE697FFD9BA39B3806B1731EEFED9347 1014024 ----a-w- C:\ProgramData\Comodo\lps4\temp\setup_clps_browser_addons_api_release-4.0.292287.4.exe === C: other files == 2014-07-22 09:02:16 8A847C88B0901E82D48373B29CA08A1E 620457 ----a-w- C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\PrivDog@AdTrustMedia.com.xpi ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-3527801987-756735660-2910266346-1000\Software\Microsoft\Windows\CurrentVersion\Run] "HPAdvisorDock"="C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe" "limewire plus+"="C:\Program Files (x86)\Limewire Plus+\limewire.exe -h" "AutoStartNPSAgent"="C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe" "Xvid"="C:\Program Files (x86)\Xvid\CheckUpdate.exe" "Facebook Update"="C:\Users\klajoelja\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "OfficeSyncProcess"="C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe /quietlaunch MSOSYNC 9014006604130000" "Raptr"="C:\PROGRA~2\Raptr\raptrstub.exe --startup" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun" "Norton Online Backup"="C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" "Easybits Recovery"="C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" "HP Quick Launch"="C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" "KPN Assistent"="C:\Program Files (x86)\KPN\KPN Assistent\KPN_Assistent.exe /auto" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "tvncontrol"="C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe -controlservice -slave" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "HPAdvisorDock"="C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe" "limewire plus+"="C:\Program Files (x86)\Limewire Plus+\limewire.exe -h" "AutoStartNPSAgent"="C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe" "Xvid"="C:\Program Files (x86)\Xvid\CheckUpdate.exe" "Facebook Update"="C:\Users\klajoelja\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "OfficeSyncProcess"="C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe /quietlaunch MSOSYNC 9014006604130000" "Raptr"="C:\PROGRA~2\Raptr\raptrstub.exe --startup" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=" " ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s" "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" "HPWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "NCPluginUpdater"="C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe Update" ==== Startup Folders ====================== 2014-07-01 16:09:37 2013 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [20-07-2014 18:12] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3527801987-756735660-2910266346-1000Core.job --a------ C:\Users\klajoelja\AppData\Local\Facebook\Update\FacebookUpdate.exe [12-09-2012 00:40] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3527801987-756735660-2910266346-1000UA.job --a------ C:\Users\klajoelja\AppData\Local\Facebook\Update\FacebookUpdate.exe [12-09-2012 00:40] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ :C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [] C:\Windows\tasks\HPCeeScheduleForKLAJOELJA-HP$.job --a------ [Undetermined Task] C:\Windows\tasks\HPCeeScheduleForklajoelja.job --a------ C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [05-01-2010 03:53] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-3527801987-756735660-2910266346-1000Core" [C:\Users\klajoelja\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-3527801987-756735660-2910266346-1000UA" [C:\Users\klajoelja\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\HPCeeScheduleForklajoelja" [C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe] "C:\Windows\SysNative\tasks\HPCeeScheduleForKLAJOELJA-HP$" [C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe] "C:\Windows\SysNative\tasks\NetworkWizardVCW" ["C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe"] "C:\Windows\SysNative\tasks\RecoveryCDWin7" ["C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe"] "C:\Windows\SysNative\tasks\ServicePlan" ["C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe"] "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\SysNative\tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9}" ["C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe"] "C:\Windows\SysNative\tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22}" ["C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe"] "C:\Windows\SysNative\tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}" ["C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe"] "C:\Windows\SysNative\tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}" ["C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe"] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\Update Check" [C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] "C:\Windows\SysNative\tasks\Symantec\Norton Error Analyzer 18.7.2.3" [C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\SymErr.exe] "C:\Windows\SysNative\tasks\Symantec\Norton Error Processor 18.7.2.3" [C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\SymErr.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "shortcutff@gmail.com"="C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\shortcutff@gmail.com" [] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "{e4f94d1e-2f53-401e-8885-681602c0ddd8}"="C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi" [04-04-2014 12:36] ==== Firefox Extensions ====================== ProfilePath: C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default - Undetermined - C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\speedtest4354@BestOffers - Undetermined - C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\freegames4357@BestOffers - Undetermined - C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc} - Undetermined - C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\quick_start@gmail.com - Undetermined - C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\faststartff@gmail.com - Undetermined - C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\shortcutff@gmail.com - PrivDog - %ProfilePath%\extensions\PrivDog@AdTrustMedia.com.xpi - DVDVideoSoft YouTube MP3 and Video Download - %ProfilePath%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi - New Tab - %ProfilePath%\extensions\{C4A4F5A0-4B89-4392-AFAC-D58010E349AF}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA} - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\klajoelja\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default FF0D6F82A0EC13952E83B9439100E45D - C:\Users\klajoelja\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin 18CF51689186AEB9D1D149AEB0E92D03 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL - Microsoft Office 2013 07FAA8B85F81784DEC315E04E5852F2F - C:\Users\klajoelja\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player D4BD9F86123C87ECA570418B69326F99 - C:\Windows\SysWOW64\npdeployJava1.dll - Java Deployment Toolkit 7.0.170.2 E557911A8903410D52FF9B3245954F4F - C:\Users\klajoelja\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll - Game Face Plugin 31DA97B4682187C6639BBE2215814FDA - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director 15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System ==== Deleted Firefox Extensions ====================== C:\Users\KLAJOE~1\AppData\Roaming\Mozilla\Firefox\Profiles\mypniawh.default\extensions\{C4A4F5A0-4B89-4392-AFAC-D58010E349AF}.xpi deleted ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions acfoobbgoakpihljnfedbcfaipcdlfhk - No path found[] bopakagnckmlgajfccecajhnimjiiedh - No path found[] cmaiofennmphjldldcpphcechfnnohja - C:\Program Files (x86)\AdTrustMedia\PrivDog\PrivDog_chrome.crx[] gaiilaahiahdejapggenmdmafpmbipje - C:\Program Files (x86)\DealPly\DealPly.crx[] jpmbfleldcgkldadpdinhjjopdfpjfjp - C:\Users\klajoelja\AppData\Local\Wajam\Chrome\wajam.crx[] mhkaekfpcppmmioggniknbnbdbcigpkk - C:\Program Files (x86)\Common Files\Spigot\GC\coupons_2.4.crx[] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions gaiilaahiahdejapggenmdmafpmbipje - C:\Program Files (x86)\DealPly\DealPly.crx[] Quick Sidebar - klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\ainbkicbloikcngphmjfpjdemblcojdd YouTube - klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo MSS+ Extension - klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh Battlefield Heroes - klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh Google Search - klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf DealPly - klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje Slick Savings - klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk Google Wallet - klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Extended Protection - klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogfjmhfnldnajmfaofeiaepghjenbgjo Select City - klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma Gmail - klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chrome Fix ====================== C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.wajam.com_0.localstorage deleted successfully C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.wajam.com_0.localstorage-journal deleted successfully C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.babylon.com_0.localstorage deleted successfully C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.babylon.com_0.localstorage-journal deleted successfully C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma deleted successfully C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage deleted successfully C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage-journal deleted successfully C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh deleted successfully C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaiilaahiahdejapggenmdmafpmbipje deleted successfully C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gaiilaahiahdejapggenmdmafpmbipje_0.localstorage deleted successfully C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gaiilaahiahdejapggenmdmafpmbipje_0.localstorage-journal deleted successfully C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk deleted successfully C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mhkaekfpcppmmioggniknbnbdbcigpkk deleted successfully C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Extensions\ainbkicbloikcngphmjfpjdemblcojdd deleted successfully C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ainbkicbloikcngphmjfpjdemblcojdd_0.localstorage deleted successfully C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ainbkicbloikcngphmjfpjdemblcojdd_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.nl/?gfe_rd=cr&ei=S0K5U8zDBMHl-ga15IGIBg&gws_rd=ssl" "Default_Page_URL"="http://www.delta-homes.com/?type=hp&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N" "Search Page"="http://search.delta-homes.com/web/?type=ds&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N&q={searchTerms}" "Default_Search_URL"="http://search.delta-homes.com/web/?type=ds&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N&q={searchTerms}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.sweet-page.com/web/?type=ds&ts=1396706311&from=sof&uid=ST9500325AS_6VECVB1N&q={searchTerms}" "Default_Page_URL"="http://www.delta-homes.com/?type=hp&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N" "Start Page"="http://www.delta-homes.com/?type=hp&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N" "Search Page"="http://www.sweet-page.com/web/?type=ds&ts=1396706311&from=sof&uid=ST9500325AS_6VECVB1N&q={searchTerms}" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.sweet-page.com/web/?type=ds&ts=1396706311&from=sof&uid=ST9500325AS_6VECVB1N&q={searchTerms}" "Default_Page_URL"="http://www.delta-homes.com/?type=hp&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N" "Start Page"="http://www.delta-homes.com/?type=hp&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N" "Search Page"="http://www.sweet-page.com/web/?type=ds&ts=1396706311&from=sof&uid=ST9500325AS_6VECVB1N&q={searchTerms}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{33BB0A4E-99AF-4226-BDF6-49120163DE86}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="https://www.google.nl/?gfe_rd=cr&ei=S0K5U8zDBMHl-ga15IGIBg&gws_rd=ssl" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {1AA3FD2F-765C-4220-9708-6CA18C2858D7} Bing Url="http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox" {33524C00-63FB-43DB-A6BF-0A4E14B24649} BasicScan Url="http://www.basicscan.com/?prt=BscscnPB&keywords={searchTerms}" {A8E80A60-496A-4EE0-AC1E-BDEBA067E4A6} Google Url="http://www.google.co.uk/search?hl=en&q={searchTerms}&meta=" {E5D84A15-4AF1-419A-A84A-4226F9535272} Wikipedia Url="http://nl.wikipedia.org/wiki/Special:Search?search={searchTerms}" ==== Deleting CLSID Registry Keys ====================== HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{99079A25-328F-4BD4-BE04-00955ACAA0A7} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\quick_start@gmail.com deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\faststartff@gmail.com deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\shortcutff@gmail.com deleted successfully ==== shortcuts on Users Desktops ====================== C:\Users\klajoelja\Desktop\337 GAMES.lnk - C:\Users\klajoelja\AppData\Roaming\337Games\337Games.exe -url="http://goo.mx/aEBnEf" C:\Users\klajoelja\Desktop\DVDVideoSoft Free Studio.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\FreeStudioManager.exe C:\Users\klajoelja\Desktop\Free YouTube to MP3 Converter.lnk - C:\Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe C:\Users\klajoelja\Desktop\HP Support Assistant.lnk - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe C:\Users\klajoelja\Desktop\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe http://www.delta-homes.com/?type=sc&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N C:\Users\klajoelja\Desktop\Microsoft Excel Starter 2010.lnk - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE "Microsoft Excel Starter 2010 9014006604130000" C:\Users\klajoelja\Desktop\Microsoft Word Starter 2010.lnk - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE "Microsoft Word Starter 2010 9014006604130000" C:\Users\klajoelja\Desktop\Paint.lnk - C:\Windows\system32\mspaint.exe C:\Users\klajoelja\Desktop\Raptr.lnk - C:\Program Files (x86)\Raptr\raptrstub.exe C:\Users\klajoelja\Desktop\Speed Test.lnk - C:\Users\klajoelja\Desktop\Video Performer.lnk - C:\Program Files (x86)\Video Performer\Video Performer.exe C:\Users\klajoelja\Desktop\Jarno's eigen mapje\Paint (2).lnk - C:\Windows\system32\mspaint.exe C:\Users\klajoelja\Desktop\Jarno's eigen mapje\YouCam.lnk - C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe C:\Users\klajoelja\Desktop\My Shared Folder\internet.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe ==== shortcuts on All Users Desktop ====================== C:\Users\Public\Desktop\Adobe Reader XI.lnk - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe C:\Users\Public\Desktop\CDBurnerXP.lnk - C:\CDBurnerXP\cdbxpp.exe C:\Users\Public\Desktop\Comodo Dragon.lnk - C:\Program Files (x86)\Comodo\Dragon\dragon.exe C:\Users\Public\Desktop\GeekBuddy.lnk - C:\Program Files (x86)\COMODO\GeekBuddy\launcher.exe "unit_manager.exe" "lps-ca" C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.delta-homes.com/?type=sc&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N C:\Users\Public\Desktop\Google Earth.lnk - C:\Program Files (x86)\Google\Google Earth\client\googleearth.exe C:\Users\Public\Desktop\Internetbrowser selecteren.lnk - C:\Windows\System32\browserchoice.exe /launch C:\Users\Public\Desktop\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe C:\Users\Public\Desktop\KPN Assistant.lnk - C:\Program Files (x86)\KPN\KPN Assistent\KPN_Assistent.exe C:\Users\Public\Desktop\KPN Installatie Assistent.lnk - C:\Program Files (x86)\KPN\KPN Installatie Assistent\KPN_IA.exe C:\Users\Public\Desktop\LayOut 2014.lnk - C:\Program Files (x86)\SketchUp\SketchUp 2014\LayOut\LayOut.exe C:\Users\Public\Desktop\Magic Desktop.lnk - C:\Program Files (x86)\EasyBits For Kids\ezSecShield.exe C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.8.150\McUICnt.exe SecurityScanner.dll C:\Users\Public\Desktop\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe http://www.delta-homes.com/?type=sc&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N C:\Users\Public\Desktop\Norton Internet Security.lnk - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\uistub.exe C:\Users\Public\Desktop\PC Performer.lnk - C:\Program Files (x86)\PC Performer\PCPerformer.exe C:\Users\Public\Desktop\Picasa 3.lnk - C:\Program Files (x86)\Google\Picasa3\Picasa3.exe C:\Users\Public\Desktop\Play HP Games.lnk - C:\Program Files (x86)\HP Games\onplay\onplay.exe "C:\Program Files (x86)\HP Games\HP Game Console\GameConsole-wt.exe" /src desktopoem C:\Users\Public\Desktop\Samsung New PC Studio.lnk - C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSGuide.exe C:\Users\Public\Desktop\SketchUp 2014.lnk - C:\Program Files (x86)\SketchUp\SketchUp 2014\SketchUp.exe C:\Users\Public\Desktop\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\Public\Desktop\Style Builder 2014.lnk - C:\Program Files (x86)\SketchUp\SketchUp 2014\Style Builder\Style Builder.exe C:\Users\Public\Desktop\Verzoek of wijziging voorlopige aanslag 2013.lnk - C:\Program Files (x86)\Belastingdienst\Verzoek of wijziging voorlopige aanslag\2013\va2013.exe C:\Users\Public\Desktop\Vuze.lnk - C:\Program Files (x86)\Vuze\Azureus.exe C:\Users\Public\Desktop\YTD YouTube Downloader & Converter.lnk - C:\Program Files (x86)\YTD YouTube Downloader & Converter\ytd.exe ==== shortcuts in Users Start Menu ====================== C:\Users\klajoelja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk - C:\Program Files\Internet Explorer\iexplore.exe http://www.delta-homes.com/?type=sc&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N C:\Users\klajoelja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.delta-homes.com/?type=sc&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N C:\Users\klajoelja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\337Games\337 GAMES.lnk - C:\Users\klajoelja\AppData\Roaming\337Games\337Games.exe -url="http://goo.mx/aEBnEf" C:\Users\klajoelja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\337Games\uninstall.lnk - C:\Users\klajoelja\AppData\Roaming\337Games\uninstall.exe ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo\Dragon\Comodo Dragon.lnk - C:\Program Files (x86)\Comodo\Dragon\dragon.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo\Dragon\Uninstall Comodo Dragon.lnk - C:\Program Files (x86)\Comodo\Dragon\uninstall.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo\GeekBuddy\GeekBuddy.lnk - C:\Program Files (x86)\COMODO\GeekBuddy\launcher.exe "unit_manager.exe" "lps-ca" C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk - C:\Program Files (x86)\COMODO\GeekBuddy\launcher.exe "unit_manager.exe" ==== shortcuts in Quick Launch ====================== C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\337 GAMES.lnk - C:\Users\klajoelja\AppData\Roaming\337Games\337Games.exe -url="http://goo.mx/aEBnEf" C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.delta-homes.com/?type=sc&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.delta-homes.com/?type=sc&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung New PC Studio.lnk - C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSGuide.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk - C:\Program Files (x86)\Vuze\Azureus.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\Windows\system32\control.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9d91276b0be3e46b\pinned.lnk - C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\337 GAMES.lnk - C:\Users\klajoelja\AppData\Roaming\337Games\337Games.exe -url="http://goo.mx/aEBnEf" C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Calculator.lnk - C:\Windows\system32\calc.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Free launcher for Minecraft Alpha.lnk - C:\Users\klajoelja\Desktop\minecraft.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer (64-bit).lnk - C:\Program Files\Internet Explorer\iexplore.exe http://www.sweet-page.com/?type=sc&ts=1396706311&from=sof&uid=ST9500325AS_6VECVB1N C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Microsoft Word Starter 2010.lnk - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE "Microsoft Word Starter 2010 9014006604130000" C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Picasa 3.lnk - C:\Program Files (x86)\Google\Picasa3\Picasa3.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Raptr.lnk - C:\Program Files (x86)\Raptr\raptrstub.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\337 GAMES.lnk - C:\Users\klajoelja\AppData\Roaming\337Games\337Games.exe -url="http://goo.mx/aEBnEf" C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Free launcher for Minecraft Alpha.lnk - C:\Users\klajoelja\Desktop\minecraft.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe http://www.delta-homes.com/?type=sc&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (64-bit).lnk - C:\Program Files\Internet Explorer\iexplore.exe http://www.delta-homes.com/?type=sc&ts=1402618845&from=wpm0612&uid=ST9500325AS_6VECVB1N C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Word Starter 2010.lnk - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE "Microsoft Word Starter 2010 9014006604130000" C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Notepad.lnk - C:\Windows\system32\notepad.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Skype.lnk - C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\Windows\explorer.exe ==== shortcuts After Repair ====================== C:\Users\klajoelja\Desktop\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Public\Desktop\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer (64-bit).lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\klajoelja\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer (64-bit).lnk - C:\Program Files\Internet Explorer\iexplore.exe ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F60730A4A66673047777F5728467D401 deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\acfoobbgoakpihljnfedbcfaipcdlfhk deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\cmaiofennmphjldldcpphcechfnnohja deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Comodo\Dragon\Extensions\cmaiofennmphjldldcpphcechfnnohja deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SupTab deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup deleted successfully HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Wajam deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PC Performer_is1 deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\sweet-page uninstaller deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10} deleted successfully HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Softonic for Windows deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401 deleted successfully ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\IPS\IPSBHO.DLL O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe O4 - HKLM\..\Run: [KPN Assistent] C:\Program Files (x86)\KPN\KPN Assistent\KPN_Assistent.exe /auto O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [tvncontrol] "C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave O4 - HKCU\..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe O4 - HKCU\..\Run: [limewire plus+] "C:\Program Files (x86)\Limewire Plus+\limewire.exe" -h O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe O4 - HKCU\..\Run: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe O4 - HKCU\..\Run: [Facebook Update] "C:\Users\klajoelja\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver O4 - HKCU\..\Run: [OfficeSyncProcess] "C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe" /quietlaunch "MSOSYNC 9014006604130000" O4 - HKCU\..\Run: [Raptr] C:\PROGRA~2\Raptr\raptrstub.exe --startup O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - Global Startup: Start GeekBuddy.lnk = C:\Program Files\COMODO\GeekBuddy\launcher.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000 O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\klajoelja\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105 O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: COMODO LPS Launcher (CLPSLauncher) - Comodo Security Solutions, Inc. - C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe O23 - Service: COMODO Internet Security Helper Service (CmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (file missing) O23 - Service: COMODO Virtual Service Manager (cmdvirth) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe (file missing) O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Unknown owner - C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe O23 - Service: GeekBuddyRSP Server (GeekBuddyRSP) - Comodo Security Solutions, Inc. - C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: RtVOsdService Installer (RtVOsdService) - Realtek Semiconductor Corp. - C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\klajoelja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\klajoelja\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\klajoelja\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\klajoelja\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\klajoelja\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\klajoelja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DWW5JQ34 will be deleted at reboot C:\Users\klajoelja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NRJIREDK will be deleted at reboot C:\Users\klajoelja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\klajoelja\AppData\Local\Mozilla\Firefox\Profiles\mypniawh.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\klajoelja\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=3570 folders=875 584919481 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\klajoelja\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\KLAJOE~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\klajoelja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\Users\klajoelja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DWW5JQ34" not found "C:\Users\klajoelja\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NRJIREDK" not found ==== EOF on di 22-07-2014 at 11:51:18,13 ======================