Zoek.exe v5.0.0.0 Updated 05-October-2014 Tool run by Luce on ma 06/10/2014 at 21:49:26,13. Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Luce\Downloads\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 6/10/2014 21:52:14 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\Program Files\1Password deleted successfully C:\Program Files\AVS4YOU deleted successfully C:\Program Files\Karen's Power Tools deleted successfully C:\Program Files\MSXML 4.0 deleted successfully C:\Program Files\PhoXo deleted successfully C:\PROGRA~2\Karen's Power Tools deleted successfully C:\PROGRA~2\OEM Links deleted successfully C:\PROGRA~2\Oracle deleted successfully C:\Users\Administrator\AppData\Roaming\AdobeUM deleted successfully C:\Users\Administrator\AppData\Roaming\Canon deleted successfully C:\Users\Bart & Leen\AppData\Roaming\AdobeUM deleted successfully C:\Users\Luce\AppData\Roaming\AdobeUM deleted successfully C:\Users\Luce\AppData\Roaming\Agile Web Solutions deleted successfully C:\Users\Luce\AppData\Roaming\istartsurf deleted successfully C:\Users\Luce\AppData\Roaming\WebExtend deleted successfully C:\Users\Administrator\AppData\Local\{7AA094A8-55AF-41F3-A0CA-B1044E60B08B} deleted successfully C:\Users\Bart & Leen\AppData\Local\{054DBD0B-9286-4A2E-A24A-348235598065} deleted successfully C:\Users\Bart & Leen\AppData\Local\{06C1F011-4441-4255-BB0C-C94552DF97AD} deleted successfully C:\Users\Bart & Leen\AppData\Local\{076B1F77-9D36-4F5A-A46A-DCB7991E163B} deleted successfully C:\Users\Bart & Leen\AppData\Local\{080083A5-F8AF-4BB0-B53D-E35E1F654C3D} deleted successfully C:\Users\Bart & Leen\AppData\Local\{0B5F8A3F-2150-468F-B579-1BD2E2B692CD} deleted successfully C:\Users\Bart & Leen\AppData\Local\{0E9C1F2B-5DAF-4B5E-B523-8ECCD2E4FAAF} deleted successfully C:\Users\Bart & Leen\AppData\Local\{108A25F1-2427-4F71-961A-7D13F80F16B9} deleted successfully C:\Users\Bart & Leen\AppData\Local\{11B4EB29-BC9F-4F34-86C1-808354EB385A} deleted successfully C:\Users\Bart & Leen\AppData\Local\{11F33154-8410-42EC-A60A-965AD9C224E4} deleted successfully C:\Users\Bart & Leen\AppData\Local\{15FD5242-68A5-4B22-A906-6134371219DE} deleted successfully C:\Users\Bart & Leen\AppData\Local\{1861FEE1-C480-447C-9386-50E002B8F3C4} deleted successfully C:\Users\Bart & Leen\AppData\Local\{1A150517-267C-4AFC-98EF-6B9EC61CE2DD} deleted successfully C:\Users\Bart & Leen\AppData\Local\{1BAB0606-30F9-4100-B9E9-FF9439867A55} deleted successfully C:\Users\Bart & Leen\AppData\Local\{1C203597-40A1-4C1D-95F2-C46647D4620B} deleted successfully C:\Users\Bart & Leen\AppData\Local\{1CE760E4-0E3E-48F5-BDE4-FA9377A6A6AF} deleted successfully C:\Users\Bart & Leen\AppData\Local\{23CC1544-C49A-440D-ADEE-0983D7512BE8} deleted successfully C:\Users\Bart & Leen\AppData\Local\{25F22778-926D-4698-9D2D-1E2B82132B8F} deleted successfully C:\Users\Bart & Leen\AppData\Local\{292E4C49-2CC0-41AB-80FE-1709B9AF36E1} deleted successfully C:\Users\Bart & Leen\AppData\Local\{29CD2DD3-C668-47F9-A597-87A7749EDDF5} deleted successfully C:\Users\Bart & Leen\AppData\Local\{2C24BE13-AFDB-4786-BF11-35EA9ED1BBAE} deleted successfully C:\Users\Bart & Leen\AppData\Local\{2C83C23A-1CB2-4756-9E20-CF47E12F1034} deleted successfully C:\Users\Bart & Leen\AppData\Local\{2EDE5900-4C43-4277-BB41-CDCFC98C5E5D} deleted successfully C:\Users\Bart & Leen\AppData\Local\{2F9EE83A-39E9-4894-8108-567A58B88D67} deleted successfully C:\Users\Bart & Leen\AppData\Local\{3193A0B3-A87F-47CB-8B34-85FA3B76EB35} deleted successfully C:\Users\Bart & Leen\AppData\Local\{31B8A52F-EB29-4FA9-B775-2C00C9115D68} deleted successfully C:\Users\Bart & Leen\AppData\Local\{323C0EB2-456C-4542-B288-0A46D09CDE97} deleted successfully C:\Users\Bart & Leen\AppData\Local\{34A0CD32-5FF9-4A0C-9B86-3E9B93BF7A6D} deleted successfully C:\Users\Bart & Leen\AppData\Local\{3516FEAF-2166-4EB1-B47D-A8407422B105} deleted successfully C:\Users\Bart & Leen\AppData\Local\{3547BA88-A2F5-4323-A753-3B1BFE1F1ED3} deleted successfully C:\Users\Bart & Leen\AppData\Local\{38CA63BA-2ED0-4A38-99F3-D56101A61AE1} deleted successfully C:\Users\Bart & Leen\AppData\Local\{3A18F2D2-F719-486E-A9DA-3B84672B2590} deleted successfully C:\Users\Bart & Leen\AppData\Local\{3AD97974-83EB-4228-A141-AD1B66DE25D5} deleted successfully C:\Users\Bart & Leen\AppData\Local\{3C7963FD-1178-4D4F-9B41-2A3783ED08A7} deleted successfully C:\Users\Bart & Leen\AppData\Local\{3CC3BE98-3D03-4AF4-90ED-BB7641D6ECC4} deleted successfully C:\Users\Bart & Leen\AppData\Local\{3FF7EA7A-E65A-4EFC-9D0B-52CD2295E325} deleted successfully C:\Users\Bart & Leen\AppData\Local\{431FA9E1-CCF5-4BAE-B029-B485FEF15F4C} deleted successfully C:\Users\Bart & Leen\AppData\Local\{44503ECD-9429-447F-A19E-2858271A7D9E} deleted successfully C:\Users\Bart & Leen\AppData\Local\{46749D1C-E9EE-4A52-8E68-3D5D9E8C4A4A} deleted successfully C:\Users\Bart & Leen\AppData\Local\{467C97C6-E3E6-4853-8E36-64AEFD533117} deleted successfully C:\Users\Bart & Leen\AppData\Local\{47A599B1-7815-492D-9A2C-853927449C1D} deleted successfully C:\Users\Bart & Leen\AppData\Local\{488EA7C5-7EF8-4135-ADB2-4299F9FD6999} deleted successfully C:\Users\Bart & Leen\AppData\Local\{4A645664-4236-42DF-9911-087CC20BAE75} deleted successfully C:\Users\Bart & Leen\AppData\Local\{4D2A9F2E-EEFC-47FF-AB7E-F422225FBF56} deleted successfully C:\Users\Bart & Leen\AppData\Local\{4E02962A-E470-4EEA-A0E8-9E32DB168F26} deleted successfully C:\Users\Bart & Leen\AppData\Local\{57C964C7-CAD5-4C54-8472-04895DC4CE6A} deleted successfully C:\Users\Bart & Leen\AppData\Local\{58C7BB7C-3080-4DC8-B085-CC08E1E3E8C2} deleted successfully C:\Users\Bart & Leen\AppData\Local\{59450310-896E-4C85-9C81-C1520D25C09A} deleted successfully C:\Users\Bart & Leen\AppData\Local\{599A08F9-6803-43E5-A79C-B804D1A31657} deleted successfully C:\Users\Bart & Leen\AppData\Local\{59F0B3FF-A474-4525-9064-6E877801EBE7} deleted successfully C:\Users\Bart & Leen\AppData\Local\{5A154440-C4AF-4A37-A740-AC2BDF74B69F} deleted successfully C:\Users\Bart & Leen\AppData\Local\{5F03E0AD-7037-443E-A943-145B89F0D4A8} deleted successfully C:\Users\Bart & Leen\AppData\Local\{602C8F7D-A6F4-4E78-949B-38E3E7B32478} deleted successfully C:\Users\Bart & Leen\AppData\Local\{60694153-3B1B-42B0-A39D-4C48B08FEB86} deleted successfully C:\Users\Bart & Leen\AppData\Local\{63178B88-1F91-4813-B3CE-EC9EFAA70DF0} deleted successfully C:\Users\Bart & Leen\AppData\Local\{634058A2-BC84-4B44-BE3B-D2ABEF1A57F9} deleted successfully C:\Users\Bart & Leen\AppData\Local\{65336B53-8EB9-444D-8EB1-17000A76ACEF} deleted successfully C:\Users\Bart & Leen\AppData\Local\{673635E0-8DC3-469D-94A4-3663C49AC78A} deleted successfully C:\Users\Bart & Leen\AppData\Local\{67DD87E9-C07F-4336-88A3-0571600C3595} deleted successfully C:\Users\Bart & Leen\AppData\Local\{688873B4-F236-47BF-B056-80022477F7E0} deleted successfully C:\Users\Bart & Leen\AppData\Local\{68E4D473-E13D-40CB-9663-51BDA9C5789A} deleted successfully C:\Users\Bart & Leen\AppData\Local\{6C49F53B-9044-4200-905A-22D9F2607D7D} deleted successfully C:\Users\Bart & Leen\AppData\Local\{6FA2DFA0-65F9-4541-BC48-652CAAA928EF} deleted successfully C:\Users\Bart & Leen\AppData\Local\{6FE4951F-FC90-44FC-A48B-9002579D90A2} deleted successfully C:\Users\Bart & Leen\AppData\Local\{7141710E-D13F-408A-882A-E4E95009AC7C} deleted successfully C:\Users\Bart & Leen\AppData\Local\{714FB0F5-EDB8-4924-ABD2-71017AD5ACB1} deleted successfully C:\Users\Bart & Leen\AppData\Local\{71800990-C35D-4881-A470-20E0C8F0A1FF} deleted successfully C:\Users\Bart & Leen\AppData\Local\{73769B7A-7B4B-42A7-9FA9-40AF348058F5} deleted successfully C:\Users\Bart & Leen\AppData\Local\{77C4CD86-013F-4FD6-B358-40F3FBBE11A1} deleted successfully C:\Users\Bart & Leen\AppData\Local\{78E428B6-AD57-42F7-8247-EA5CC34D4D40} deleted successfully C:\Users\Bart & Leen\AppData\Local\{79E5476F-FCEA-496F-B467-9097EF518B9C} deleted successfully C:\Users\Bart & Leen\AppData\Local\{7C26FE39-25FA-4C13-87A3-2CF7BE1767D6} deleted successfully C:\Users\Bart & Leen\AppData\Local\{7C3329E8-68D1-4211-BEC6-E2BB78A88F0A} deleted successfully C:\Users\Bart & Leen\AppData\Local\{7C3D6B0F-0CCD-4410-83BD-9DAFD8EBE965} deleted successfully C:\Users\Bart & Leen\AppData\Local\{7F3D1479-B609-455F-A1A1-9702FBE0F637} deleted successfully C:\Users\Bart & Leen\AppData\Local\{8103A12A-63B1-48D1-9359-FE5FA57BFB5A} deleted successfully C:\Users\Bart & Leen\AppData\Local\{87292E87-F2D8-488D-B09B-8D4967D34CEB} deleted successfully C:\Users\Bart & Leen\AppData\Local\{8924B16F-86F1-4702-9A41-743ED525185A} deleted successfully C:\Users\Bart & Leen\AppData\Local\{89D600DC-26CA-40CC-B28E-A5ADDF30C0D5} deleted successfully C:\Users\Bart & Leen\AppData\Local\{8AB40B35-82C7-42B6-833C-0D543C7F6523} deleted successfully C:\Users\Bart & Leen\AppData\Local\{8B3F9B94-0F0A-42BD-89B8-B5D42AABF5A5} deleted successfully C:\Users\Bart & Leen\AppData\Local\{8C1ACEE8-FA24-4D13-9D76-D692EC479194} deleted successfully C:\Users\Bart & Leen\AppData\Local\{903F4BA4-D6E0-4D3B-B653-41D2BA0CBD50} deleted successfully C:\Users\Bart & Leen\AppData\Local\{90AE230D-2006-42C2-9BF3-8F88AB371021} deleted successfully C:\Users\Bart & Leen\AppData\Local\{9246A7E0-4CDA-4D82-99CE-717F0A35A9E4} deleted successfully C:\Users\Bart & Leen\AppData\Local\{937EEB6F-D3D9-47A7-8032-0194F38F6656} deleted successfully C:\Users\Bart & Leen\AppData\Local\{9A48D233-A24F-4000-AF7F-154BC54AB454} deleted successfully C:\Users\Bart & Leen\AppData\Local\{9ADFB38F-28A5-4CB1-95E7-039EB272C4D9} deleted successfully C:\Users\Bart & Leen\AppData\Local\{9B0C449B-C24C-4D01-904F-E72A9681B024} deleted successfully C:\Users\Bart & Leen\AppData\Local\{9BBA8588-DD81-4710-AE66-926A210778A6} deleted successfully C:\Users\Bart & Leen\AppData\Local\{9BF77387-89EB-450F-A57D-9F5E9ADF4116} deleted successfully C:\Users\Bart & Leen\AppData\Local\{9E232501-9E33-4BED-8967-87B98554C79A} deleted successfully C:\Users\Bart & Leen\AppData\Local\{9F4FB7CF-B5F2-4374-9E68-18DE975F1533} deleted successfully C:\Users\Bart & Leen\AppData\Local\{A0866427-85D7-4C2A-BED8-B4B67A2BF93B} deleted successfully C:\Users\Bart & Leen\AppData\Local\{A0FB1DF9-D56F-4123-8582-168F310B803D} deleted successfully C:\Users\Bart & Leen\AppData\Local\{A18E651E-A973-46A1-998C-23423CB57A14} deleted successfully C:\Users\Bart & Leen\AppData\Local\{A1E0D3F3-759E-4447-980F-8AA427D84FA7} deleted successfully C:\Users\Bart & Leen\AppData\Local\{A2F33A8A-991E-46C1-95DA-FEB7C6F60870} deleted successfully C:\Users\Bart & Leen\AppData\Local\{A6F01BD6-2C78-4F4D-AF9D-2BD1FFE20C15} deleted successfully C:\Users\Bart & Leen\AppData\Local\{A946A4AB-DD67-40E1-800A-1B26B165D834} deleted successfully C:\Users\Bart & Leen\AppData\Local\{A96FEC66-ACAA-47B7-AD3F-2B9C5966A148} deleted successfully C:\Users\Bart & Leen\AppData\Local\{AB139552-C3A6-48DA-AE1A-CBA91C53A268} deleted successfully C:\Users\Bart & Leen\AppData\Local\{ADE33819-5C14-4D80-B10E-AB7BCF474CCC} deleted successfully C:\Users\Bart & Leen\AppData\Local\{AF7386E2-54DC-4509-A5F3-FA95E81F2DDF} deleted successfully C:\Users\Bart & Leen\AppData\Local\{B18C5B58-82AA-4F7E-8BB2-4FF8958E5CCF} deleted successfully C:\Users\Bart & Leen\AppData\Local\{B3C319C8-3DFA-46F1-B133-D6960C7D7B27} deleted successfully C:\Users\Bart & Leen\AppData\Local\{B490DFEE-3281-49C9-A993-92699078C0E0} deleted successfully C:\Users\Bart & Leen\AppData\Local\{B4E0A5F1-FDEF-4B19-A0CE-E54BCA0E677C} deleted successfully C:\Users\Bart & Leen\AppData\Local\{B6335F93-8FE5-49BB-AAAF-34E24D38A388} deleted successfully C:\Users\Bart & Leen\AppData\Local\{B6ECB3D3-5CD3-4DF5-B2F7-0E0FC710A16C} deleted successfully C:\Users\Bart & Leen\AppData\Local\{B9B1D1F7-3A6C-409B-A218-1A562828C0F1} deleted successfully C:\Users\Bart & Leen\AppData\Local\{B9EDC57A-94D3-46AF-A54D-FAC0AEB8B09B} deleted successfully C:\Users\Bart & Leen\AppData\Local\{BC413B49-D11B-4376-AAF1-C8ACCF9F0BD9} deleted successfully C:\Users\Bart & Leen\AppData\Local\{BF75FC96-2FC7-461E-A7D1-467169A7319B} deleted successfully C:\Users\Bart & Leen\AppData\Local\{C02E90D5-C601-4210-A149-120F0618B2D3} deleted successfully C:\Users\Bart & Leen\AppData\Local\{C318333D-D585-4458-8DBD-CCD96E6CEA68} deleted successfully C:\Users\Bart & Leen\AppData\Local\{C3F66ED4-3237-4683-B58A-643FDA4E0E1C} deleted successfully C:\Users\Bart & Leen\AppData\Local\{C5686D67-375F-4D4F-A03E-4DB4AB4DCCA3} deleted successfully C:\Users\Bart & Leen\AppData\Local\{C58231D5-3193-4022-987D-4793BCBF3714} deleted successfully C:\Users\Bart & Leen\AppData\Local\{C62F4E1C-826A-4CD5-AED1-96D37BDBF947} deleted successfully C:\Users\Bart & Leen\AppData\Local\{C71B1B3A-0131-4D7B-AA45-0B42E83A60F4} deleted successfully C:\Users\Bart & Leen\AppData\Local\{C794AC80-A6F4-4251-AA7D-B2F6D8B08DF4} deleted successfully C:\Users\Bart & Leen\AppData\Local\{C7E4DF47-D1C5-4B1F-8FA6-BE392B2FB203} deleted successfully C:\Users\Bart & Leen\AppData\Local\{C9A12F0A-3AF3-4E56-83FB-86477692C7F3} deleted successfully C:\Users\Bart & Leen\AppData\Local\{CA1772E3-9F20-424D-86F6-BCBDD7591612} deleted successfully C:\Users\Bart & Leen\AppData\Local\{CA25AA99-B064-4A0C-8FDA-8A4FA9540A9B} deleted successfully C:\Users\Bart & Leen\AppData\Local\{CBA557D6-DEEF-4A2A-AE64-4D9A3E8F1A78} deleted successfully C:\Users\Bart & Leen\AppData\Local\{CC3C508A-20D3-4CC6-A3BF-0482667F2E76} deleted successfully C:\Users\Bart & Leen\AppData\Local\{CC833F91-17A0-4831-8943-B58E9B12B8F3} deleted successfully C:\Users\Bart & Leen\AppData\Local\{CEB56D2B-14A6-47C9-941F-7CE2B6FAB163} deleted successfully C:\Users\Bart & Leen\AppData\Local\{D2DC4F02-2659-4D81-A5E7-565DDA17A9A5} deleted successfully C:\Users\Bart & Leen\AppData\Local\{D4787A3A-19C2-4DAC-AADC-5E295F1B048E} deleted successfully C:\Users\Bart & Leen\AppData\Local\{DA60C797-79BF-49E6-8E53-D74751551F5F} deleted successfully C:\Users\Bart & Leen\AppData\Local\{DBDA46FA-4D5C-484F-94BB-59CA7173F37E} deleted successfully C:\Users\Bart & Leen\AppData\Local\{DC5003AF-99DB-4A66-81EB-99F8ED8BF14B} deleted successfully C:\Users\Bart & Leen\AppData\Local\{DD35F50B-3AA8-4B06-8858-E013965CBC75} deleted successfully C:\Users\Bart & Leen\AppData\Local\{DDE3C02E-B247-40E6-8EE1-BB2D1E7C9539} deleted successfully C:\Users\Bart & Leen\AppData\Local\{DE1EB5A9-E672-4F4A-94C9-1633E03F5C3A} deleted successfully C:\Users\Bart & Leen\AppData\Local\{DEBF4892-B785-4909-8ED4-8F7F1C41449C} deleted successfully C:\Users\Bart & Leen\AppData\Local\{E18CE5C0-E1F0-46BB-9AFD-869D8D9DCD14} deleted successfully C:\Users\Bart & Leen\AppData\Local\{E35C4E14-EA33-4066-AB21-BD68B1452153} deleted successfully C:\Users\Bart & Leen\AppData\Local\{E35ECB55-DF64-4FB5-AF2B-9CB4759F8DB5} deleted successfully C:\Users\Bart & Leen\AppData\Local\{E60DEA0A-1C18-4CEF-BD89-A46876B965CA} deleted successfully C:\Users\Bart & Leen\AppData\Local\{E8BDCC36-5837-497F-8F2E-B8B34742B812} deleted successfully C:\Users\Bart & Leen\AppData\Local\{EA644626-D5EB-49A4-9BF7-58291F3C4CDA} deleted successfully C:\Users\Bart & Leen\AppData\Local\{EBA974D2-889F-43C3-818F-9D0AB2F3FE19} deleted successfully C:\Users\Bart & Leen\AppData\Local\{EC52DBBC-06F5-4202-9E84-E137AA9C59FE} deleted successfully C:\Users\Bart & Leen\AppData\Local\{EF3667AE-5F6D-425D-AE6E-679EBE7DCFAD} deleted successfully C:\Users\Bart & Leen\AppData\Local\{F45638FD-ABF1-4AE3-90BD-79254C173087} deleted successfully C:\Users\Bart & Leen\AppData\Local\{F47733CD-58AC-4AE2-B510-6A47B9D9EE64} deleted successfully C:\Users\Bart & Leen\AppData\Local\{F6146ACE-B415-4F59-98A6-FEE7008A51B6} deleted successfully C:\Users\Bart & Leen\AppData\Local\{FDF7F515-9BBE-49F3-8EB4-D08407616C6F} deleted successfully C:\Users\Bart & Leen\AppData\Local\{FF126181-3DB7-44F9-8440-12010B2036BD} deleted successfully C:\Users\Bart & Leen\AppData\Local\{FF3440F2-8C1B-4C0A-AC87-6F2F8A45E772} deleted successfully C:\Users\Luce\AppData\Local\cache deleted successfully C:\Users\Luce\AppData\Local\calibre-cache deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3323627426-1777380327-1123927095-1001\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully HKEY_USERS\S-1-5-21-3323627426-1777380327-1123927095-1001\Software\Classes\VirtualStore\MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully HKEY_USERS\S-1-5-21-3323627426-1777380327-1123927095-1001\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} deleted successfully HKEY_USERS\S-1-5-21-3323627426-1777380327-1123927095-1001\Software\Microsoft\Internet Explorer\SearchScopes\{B29E60D2-6525-46AC-AF3D-46185C1F15AE} deleted successfully HKEY_USERS\S-1-5-21-3323627426-1777380327-1123927095-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1B5F1C3-6B6A-4890-A0CB-EAF0DF160E69} deleted successfully HKEY_USERS\S-1-5-21-3323627426-1777380327-1123927095-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2e32cfe5-df92-4ae5-b0be-609ed0df74a6} deleted successfully HKEY_USERS\S-1-5-21-3323627426-1777380327-1123927095-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2e32cfe5-df92-4ae5-b0be-609ed0df74a6} deleted successfully HKEY_USERS\S-1-5-21-3323627426-1777380327-1123927095-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1} deleted successfully HKEY_USERS\S-1-5-21-3323627426-1777380327-1123927095-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-3323627426-1777380327-1123927095-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{00000000-0000-0000-0000-000000000000} deleted successfully HKEY_USERS\S-1-5-21-3323627426-1777380327-1123927095-1001\Software\Mozilla\Firefox\Extensions\lspeaker@lyricsspeaker.net deleted successfully HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\12ffxtbr@MyScrapNook_12.com deleted successfully ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyScrapNook_12Service deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MyScrapNook_12Service deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IePluginServices deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\IePluginServices deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\IePluginServices deleted successfully ==== FireFox Fix ====================== ProfilePath: C:\Users\ADMINI~1\AppData\Roaming\Mozilla\Firefox\Profiles\sztsgv0g.default user.js not found ---- Lines babylon modified from prefs.js ---- user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"belgiumeid@eid.belgium.be\":{\"descriptor\":\"C:\\\\Program Files ---- Lines ask.com removed from prefs.js ---- user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WR user_pref("extensions.wrc.SearchRules.ask.com.url", "^http(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*"); ---- Lines ffxtbr modified from prefs.js ---- user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"belgiumeid@eid.belgium.be\":{\"descriptor\":\"C:\\\\Program Files ---- Lines Search-Results removed from prefs.js ---- user_pref("extensions.wrc.SearchRules.rambler.ru.style", ".WRCN {display:none} .search-results .title + .WRCN {display:inline url(\"IMAGE\") right no ---- Lines browser.startup.page removed from prefs.js ---- user_pref("browser.startup.page", 1); ---- FireFox user.js and prefs.js backups ---- prefs_20140610_2210_.backup ProfilePath: C:\Users\BART&L~1\AppData\Roaming\Mozilla\Firefox\Profiles\96kg30ij.default user.js not found ---- FireFox user.js and prefs.js backups ---- prefs_20140610_2210_.backup ProfilePath: C:\Users\Luce\AppData\Roaming\Mozilla\Firefox\Profiles\i56pb4nz.default user.js not found ---- Lines browser.startup.page removed from prefs.js ---- user_pref("browser.startup.page", 1); ---- FireFox user.js and prefs.js backups ---- prefs_20140610_2210_.backup ProfilePath: C:\Users\Luce\AppData\Roaming\Mozilla\Firefox\Profiles\ukec3ixn.default user.js not found ---- Lines isearch removed from prefs.js ---- user_pref("weboftrust.search.avg.url", "^http(s)?\\:\\/\\/isearch\\.avg\\.com\\/search\\?"); ---- FireFox user.js and prefs.js backups ---- prefs_20140610_2210_.backup ProfilePath: C:\Users\Luce\AppData\Roaming\Thunderbird\Profiles\odr5vydv.default user.js not found ---- FireFox user.js and prefs.js backups ---- prefs_20140610_2210_.backup ==== Deleting Files \ Folders ====================== C:\Users\Luce\AppData\Roaming\istartsurf not found C:\Program Files\SupTab deleted C:\ProgramData\WindowsMangerProtect deleted C:\Users\Luce\AppData\Roaming\EZDownloader deleted C:\PROGRA~2\2308189059 deleted C:\PROGRA~2\StarApp deleted C:\Users\Luce\AppData\Local\genienext deleted C:\Program Files\TornTV.com deleted C:\Users\Bart & Leen\daemonprocess.txt deleted C:\Users\Luce\daemonprocess.txt deleted C:\Users\Luce\.android deleted C:\Program Files\Mozilla Firefox\user.js deleted C:\Program Files\Mozilla Firefox\browser\searchplugins\default-search.xml deleted C:\Program Files\Mobogenie deleted C:\Program Files\BonanzaDeals deleted C:\Program Files\BonanzaDealsLive deleted C:\Program Files\globalUpdate deleted C:\Users\Luce\AppData\Roaming\FirefoxToolbar deleted C:\Users\Luce\AppData\Roaming\0F1F1C2Y1H1P1C0I0T deleted C:\Users\Luce\AppData\Roaming\newnext.me deleted C:\Users\Luce\AppData\Roaming\Systweak deleted C:\Users\Luce\AppData\Roaming\OpenCandy deleted C:\PROGRA~2\IePluginServices deleted C:\PROGRA~2\BonanzaDealsLive deleted C:\PROGRA~2\InstallMate deleted C:\PROGRA~2\Package Cache deleted C:\Users\Luce\AppData\Local\globalUpdate deleted C:\Users\Luce\AppData\Local\BonanzaDealsLive deleted C:\Users\Luce\AppData\Local\playnowradio deleted C:\Users\Luce\AppData\Local\Mobogenie deleted C:\Users\Luce\AppData\Local\Installer deleted C:\Users\Luce\AppData\Local\CrashRpt deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZDownloader deleted C:\Users\Luce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie deleted C:\Users\Luce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com deleted C:\Users\Public\Documents\GOOBZO deleted C:\Users\Public\Documents\YTAHelper deleted C:\Users\Luce\Downloads\iLividSetupV1(1).exe deleted C:\Users\Luce\Downloads\iLividSetupV1.exe deleted C:\Users\Luce\Downloads\BflixInstaller.exe deleted C:\Users\Luce\Downloads\SoftonicDownloader_voor_apowersoft-free-youtube-downloader.exe deleted C:\Users\Luce\Downloads\SoftonicDownloader_voor_atube-catcher.exe deleted C:\Users\Luce\Downloads\SoftonicDownloader_voor_calibre.exe deleted C:\Users\Luce\Downloads\SoftonicDownloader_voor_freemake-video-converter.exe deleted C:\Users\Luce\AppData\LocalLow\DataMngr deleted C:\Windows\system32\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted C:\Windows\system32\config\systemprofile\AppData\LocalLow\Application Updater deleted C:\Windows\system32\Tasks\Express FilesUpdate deleted C:\Windows\Launcher.exe deleted C:\Windows\system32\config\systemprofile\Searches deleted C:\Windows\system32\roboot.exe deleted C:\Windows\System32\AI_RecycleBin deleted C:\Windows\System32\SearchProtect deleted C:\Users\Luce\Documents\Optimizer Pro deleted C:\Users\Luce\Documents\Mobogenie deleted C:\Users\Luce\AppData\Roaming\Mozilla\Firefox\Profiles\ukec3ixn.default\searchplugins\default-search.xml deleted C:\Users\Public\Desktop\EZDownloader.lnk deleted C:\Users\Public\Desktop\Free YouTube Downloader.lnk deleted C:\Users\Public\Desktop\YTD Video Downloader.lnk deleted C:\Users\Luce\Desktop\Mobogenie.lnk deleted C:\Users\ADMINI~1\AppData\Roaming\Mozilla\Firefox\Profiles\sztsgv0g.default\extensions\{82c9cc8e-decc-41b8-b222-c21bb7922d76} deleted C:\Users\BART&L~1\AppData\Roaming\Mozilla\Firefox\Profiles\96kg30ij.default\extensions\{82c9cc8e-decc-41b8-b222-c21bb7922d76} deleted C:\Users\Luce\AppData\Roaming\Mozilla\Firefox\Profiles\ukec3ixn.default\extensions\{aef90853-1c88-47e0-97d4-0da8f83f6c66} deleted "C:\Windows\system32\drivers\SPPD.sys" deleted "C:\Windows\Installer\c9da69.msi" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Luce\AppData\Local\Temp ==== 2014-10-06 05:21:48 4E566FEA83FCEEAF2873702806B55006 43008 ----a-w- C:\Users\Luce\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp_2rrxt.dll ====== Java Cache ===== ====== C:\Windows\system32 ===== 2014-10-06 13:32:59 0DC5AF80D059DEC792B665ED598C6567 536576 ----a-w- C:\Windows\System32\sqlite3.dll 2014-10-01 15:10:29 BBA80D3CAB22620A6AC9BB603386EE33 519680 ----a-w- C:\Windows\System32\qdvd.dll 2014-09-29 09:32:52 5C8874EE321F4623FFF7A1315039DDBC 77824 ----a-w- C:\Windows\System32\fmcodec.DLL 2014-09-24 15:10:21 C263F3E7E0523556964D661BC7CB9565 2048 ----a-w- C:\Windows\System32\tzres.dll ====== C:\Windows\system32\drivers ===== ====== C:\Windows\Tasks ====== 2014-09-29 12:56:14 6F91FCBEECC752A29CD4FE583A466A2F 3100 ----a-w- C:\Windows\system32\Tasks\{6FC112FA-2BEB-4A27-833D-5409A48F89A3} 2014-09-29 09:39:55 FD3CFFB12351B0B7D3CAB2A394B316F7 3140 ----a-w- C:\Windows\system32\Tasks\{9803360B-828A-47C1-A305-9E4B8B7402CC} ====== C:\Windows\Temp ====== ======= C:\Program Files ===== ======= C: ===== ====== C:\Users\Luce\AppData\Roaming ====== ====== C:\Users\Luce ====== 2014-10-06 14:55:32 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\Luce\Downloads\RSIT(1).exe 2014-10-06 13:50:53 9AE4C48DB6D9EB7D060C71AB1AABF5F0 4965896 ----a-w- C:\Users\Luce\Downloads\ccsetup418.exe 2014-10-06 13:30:06 12EFD5FA51597F188E5DB50BE20EE597 1375089 ----a-w- C:\Users\Luce\Downloads\adwcleaner_3.311.exe 2014-10-05 13:57:55 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\Luce\Downloads\RSIT.exe 2014-09-29 19:57:23 F0D5720F3BD80639197C4F344EDF1174 81525 ----a-w- C:\Users\Luce\Downloads\SetupYTD.exe ====== C: exe-files == 2014-10-06 14:56:17 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\Trend Micro\Luce.exe 2014-10-06 14:55:32 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\Luce\Downloads\RSIT(1).exe 2014-10-06 13:50:53 9AE4C48DB6D9EB7D060C71AB1AABF5F0 4965896 ----a-w- C:\Users\Luce\Downloads\ccsetup418.exe 2014-10-06 13:30:06 12EFD5FA51597F188E5DB50BE20EE597 1375089 ----a-w- C:\Users\Luce\Downloads\adwcleaner_3.311.exe 2014-10-05 13:57:55 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\Luce\Downloads\RSIT.exe === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Copy"="C:\Users\Luce\AppData\Roaming\Copy\CopyAgent.exe" "EEDSpeedLauncher"="rundll32.exe C:\Windows\system32\eed_ec.dll,SpeedLauncher" [HKEY_USERS\S-1-5-21-3323627426-1777380327-1123927095-1001\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" "DymoQuickPrint"="C:\Program Files\DYMO\DYMO Label Software\DymoQuickPrint.exe /startup" "EEDSpeedLauncher"="rundll32.exe C:\Windows\system32\eed_ec.dll,SpeedLauncher" "LiveSupport"="C:\Program Files\LiveSupport\LiveSupport.exe /noshow /log" "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner.exe /MONITOR" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "Copy"="C:\Users\Luce\AppData\Roaming\Copy\CopyAgent.exe" "EEDSpeedLauncher"="rundll32.exe C:\Windows\system32\eed_ec.dll,SpeedLauncher" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" "BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices" "LWS"="C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide" "ConnectionCenter"="C:\Program Files\Citrix\ICA Client\concentr.exe /startup" "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "DLSService"="C:\Program Files\DYMO\DYMO Label Software\DLSService.exe" "AvastUI.exe"="C:\Program Files\Alwil Software\Avast5\AvastUI.exe /nogui" "Redirector"="C:\Program Files\Citrix\ICA Client\redirector.exe /startup" "APSDaemon"="C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe -atboottime" "SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" "DymoQuickPrint"="C:\Program Files\DYMO\DYMO Label Software\DymoQuickPrint.exe /startup" "EEDSpeedLauncher"="rundll32.exe C:\Windows\system32\eed_ec.dll,SpeedLauncher" "LiveSupport"="C:\Program Files\LiveSupport\LiveSupport.exe /noshow /log" "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner.exe /MONITOR" ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Acrobat Assistant 7.0] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Acrobat Assistant 7.0" "hkey"="HKLM" "command"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\beid] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="beid" "hkey"="HKLM" "command"="\"C:\\Program Files\\Belgium Identity Card\\beid35gui.exe\" /startup" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Facebook Update] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Facebook Update" "hkey"="HKCU" "command"="\"C:\\Users\\Luce\\AppData\\Local\\Facebook\\Update\\FacebookUpdate.exe\" /c /nocrashserver" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NeroFilterCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NeroFilterCheck" "hkey"="HKLM" "command"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Packard Bell Software Suite] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Packard Bell Software Suite" "hkey"="HKCU" "command"="\"C:\\Program Files\\Packard Bell\\Software Suite\\PBSoftSuite.exe\" /run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Software Suite] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Software Suite" "hkey"="HKCU" "command"="\"C:\\Program Files\\Packard Bell\\Software Suite\\PBSoftSuite.exe\" /RUN" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\updateMgr] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="updateMgr" "hkey"="HKCU" "command"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Acrobat\\AdobeUpdateManager.exe\" AcPro7_1_0 -reboot 1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk] "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Adobe Acrobat Speed Launcher.lnk" "backup"="C:\\Windows\\pss\\Adobe Acrobat Speed Launcher.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\Windows\\Installer\\{AC76BA86-1033-F400-7760-000000000002}\\SC_Acrobat.exe " "item"="Adobe Acrobat Speed Launcher" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Luce^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Schermopname en Snel starten.lnk] "path"="C:\\Users\\Luce\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OneNote 2010 Schermopname en Snel starten.lnk" "backup"="C:\\Windows\\pss\\OneNote 2010 Schermopname en Snel starten.lnk.Startup" "backupExtension"=".Startup" "command"="C:\\PROGRA~1\\MIF5BA~1\\Office14\\ONENOTEM.EXE /tsr" "item"="OneNote 2010 Schermopname en Snel starten" ==== Startup Folders ====================== 2014-07-30 13:47:53 1055 ----a-w- C:\Users\Luce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk 2012-05-04 17:02:31 1109 ----a-w- C:\Users\Luce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk 2013-03-27 11:38:44 1031 ----a-w- C:\Users\Luce\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stickies.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ [Undetermined Task] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3323627426-1777380327-1123927095-1001Core.job --a------ C:\Users\Luce\AppData\Local\Facebook\Update\FacebookUpdate.exe [12/07/2012 10:14] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3323627426-1777380327-1123927095-1001UA.job --a------ C:\Users\Luce\AppData\Local\Facebook\Update\FacebookUpdate.exe [12/07/2012 10:14] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [04/02/2014 17:05] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [04/02/2014 17:05] ==== Other Scheduled Tasks ====================== "C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\system32\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\system32\tasks\FacebookUpdateTaskUserS-1-5-21-3323627426-1777380327-1123927095-1001Core" [C:\Users\Luce\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\system32\tasks\FacebookUpdateTaskUserS-1-5-21-3323627426-1777380327-1123927095-1001UA" [C:\Users\Luce\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe] "C:\Windows\system32\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\Alwil Software\Avast5\WebRep\FF" [11/07/2014 17:21] ==== Firefox Extensions ====================== ProfilePath: C:\Users\ADMINI~1\AppData\Roaming\Mozilla\Firefox\Profiles\sztsgv0g.default - Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - avast Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF ProfilePath: C:\Users\BART&L~1\AppData\Roaming\Mozilla\Firefox\Profiles\96kg30ij.default - Belgium eID - C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be ProfilePath: C:\Users\Luce\AppData\Roaming\Mozilla\Firefox\Profiles\ukec3ixn.default - avast Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF - Belgium eID - C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be - Undetermined - %ProfilePath%\extensions\03252d9970f1cf1fa92ecb79f61c02b5a4a18fb0a8e61802c64bc0b07e21b615_lp.key - Undetermined - %ProfilePath%\extensions\03252d9970f1cf1fa92ecb79f61c02b5a4a18fb0a8e61802c64bc0b07e21b615_lp.key - SimilarWeb - %ProfilePath%\extensions\FirefoxAddon@similarWeb.com - Xmarks - %ProfilePath%\extensions\foxmarks@kei.com - Super Start - %ProfilePath%\extensions\superstart@enjoyfreeware.org - InFormEnter - %ProfilePath%\extensions\{5546F97E-11A5-46b0-9082-32AD74AAA920} - ReminderFox - %ProfilePath%\extensions\{ada4b710-8346-4b82-8199-5de2b400a6ae} - FoxClocks - %ProfilePath%\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1} - Evernote Web Clipper - %ProfilePath%\extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800} - Add Bookmark Here - %ProfilePath%\extensions\abhere2@moztw.org.xpi - feedly - %ProfilePath%\extensions\feedly@devhd.xpi - Pin It Button - %ProfilePath%\extensions\jid1-YcMV6ngYmQRA2w@jetpack.xpi - Pin It button - %ProfilePath%\extensions\pinterest@robertnyman.com.xpi - Status-4-Evar - %ProfilePath%\extensions\status4evar@caligonstudios.com.xpi - The Addon Bar restored - %ProfilePath%\extensions\the-addon-bar@GeekInTraining-GiT.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi AppDir: C:\Program Files\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be - Skype Click to Call - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Luce\AppData\Roaming\Mozilla\Firefox\Profiles\ukec3ixn.default 64C4ADE063A9C93D3BAE09922AD90C27 - C:\Program Files\Adobe\Reader 11.0\Reader\browser\nppdf32.dll - Adobe Acrobat 446BCAE59E26321802E000FC3E0C390A - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll - Adobe Acrobat DFC9460CC37E5C414DC4680B10C19E7A - C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll - Shockwave Flash 14D06C3796CE3F6BA8F43CDF3AD65D76 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U67 0A6E5E3BEF374AA2F47071E7374EAD7B - C:\Program Files\Java\jre7\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 7.0.670.1 3CD19649B2C3023D65E67C056457A2BC - C:\Users\Luce\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin FB5621842FDABF9F8359775573498FBC - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll - Google Update 893BF7D2261C56C24F813405D9D018E0 - C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll - Silverlight Plug-In 86FD0445C7A92516FC0BA201C79B8E9E - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll - QuickTime Plug-in 7.7.4 9FDABAD05A9623988750CCC10223BDB0 - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll - QuickTime Plug-in 7.7.4 5E1D0432C765884434A7CCD4DBDC80AA - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll - QuickTime Plug-in 7.7.4 3B293C235A80E7A5369E6AA28FEA50B1 - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll - QuickTime Plug-in 7.7.4 A80BCBED52F7DD5FDBF346A985A4E4D5 - C:\Program Files\QuickTime\Plugins\npqtplugin.dll - QuickTime Plug-in 7.7.4 FD3F83A4EC716F5F95C036EE051F3D25 - C:\Program Files\Citrix\ICA Client\npURLInterceptorPlugin.dll - Citrix URL-Redirection Helper Plugin 10909A59F2A52E95FC6C8E731BBE3E87 - C:\Program Files\Citrix\ICA Client\npicaN.dll - Citrix ICA Client 4ABE7FADC6E7D30418638FEC7DDC79CA - C:\Program Files\DYMO\DYMO Label Software\Framework\npDYMOLabelFramework.dll - DYMO Label Framework C517E5EA7CEE783F3681F62D2A362E5B - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll - Windows Live? Photo Gallery 24E990B1E6D55428001843CF7217DD81 - C:\Program Files\Microsoft\Office Live\npOLW.dll - Microsoft Office Live Plug-in for Firefox / Microsoft Office Live Plug-in for Firefox D94C362E750F8C283BF52537D3DF28B5 - C:\Users\Luce\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll - Facebook Plugin 8DA2ED6B04EA33F2EAE8BA883F903729 - C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrlui.dll - Microsoft® Silverlight ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions eofcbnmajmjmplflapaojjnihcjkigck - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswwebrepchrome-sp.crx[04/08/2014 17:22] gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx[11/07/2014 17:21] kmgeophbbmfgkjghdgfgelpipdoclljo - C:\Program Files\LyricsSpeaker\120.crx[] lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx[17/01/2012 11:45] nbmafkdmkkckhggblphicnnhlgljnoje - C:\Program Files\TornTV.com\torn2_10.crx[] ndgonipadfipmlmdfofnjnhhlgojnjdn - C:\Users\Luce\AppData\Local\Temp\ccex.crx[] SimilarWebLite - Luce\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnpicgdnjfnbkibnicdnnpkkpklkjkki avast SafePrice - Luce\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck ghnomdcacenbmilgjigehppbamfndblo - Luce\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghnomdcacenbmilgjigehppbamfndblo Vertalen.nu - Luce\AppData\Local\Google\Chrome\User Data\Default\Extensions\giapagjeblcapfphboclikepoeelhgkj Skype Click to Call - Luce\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl ==== Chromium Startpages ====================== C:\Users\Luce\AppData\Local\Google\Chrome\User Data\Default\Preferences "homepage": "http://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MBB36BE54-17CF-4C02-966D-67E9E4217EB2&SearchSource=55&CUI=&UM=6&UP=SPD79A0ADF-A9E9-4B7D-9622-C6DEC36B2889&SSPV=", "startup_urls": [ "http://www.istartsurf.com/?type=hp&ts=1411983200&from=smt&uid=WDCXWD5000AADS-00L4B1_WD-WCAUK148038280382" ], ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Default_Page_URL"="http://www.google.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://search.certified-toolbar.com?si=44393&st=home&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96" "Start Default_Page_URL"="http://search.certified-toolbar.com?si=44393&st=home&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96" "Default_Search_URL"="http://search.certified-toolbar.com?si=44393&st=chrome&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96&q=" "Search Bar"="http://search.certified-toolbar.com?si=44393&st=chrome&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96&q=" "Search Page"="http://search.certified-toolbar.com?si=44393&st=chrome&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96&q=" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.istartsurf.com/web/?type=ds&ts=1411983200&from=smt&uid=WDCXWD5000AADS-00L4B1_WD-WCAUK148038280382&q={searchTerms}" "Search Page"="http://www.istartsurf.com/web/?type=ds&ts=1411983200&from=smt&uid=WDCXWD5000AADS-00L4B1_WD-WCAUK148038280382&q={searchTerms}" "Start Default_Page_URL"="http://www.google.com" "Search Bar"="http://www.google.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI] "(Default)"="http://search.certified-toolbar.com?si=44393&st=bs&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96&q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.certified-toolbar.com?si=44393&st=bs&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96&q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="http://search.certified-toolbar.com?si=44393&st=bs&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96&q=%s" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://www.google.com" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="http://search.certified-toolbar.com?si=44393&st=bs&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96&q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://www.google.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs] "Tabs"="http://www.google.com" "newtab"="about:tabs" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search] "Start Page"="http://search.certified-toolbar.com?si=44393&st=home&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96" "Start Default_Page_URL"="http://search.certified-toolbar.com?si=44393&st=home&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96" "Default_Search_URL"="http://search.certified-toolbar.com?si=44393&st=chrome&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96&q=" "Search Bar"="http://search.certified-toolbar.com?si=44393&st=chrome&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96&q=" "Search Page"="http://search.certified-toolbar.com?si=44393&st=chrome&tid=3786&ver=2.9&ts=1368279163388&tguid=44393-3786-1368279163388-FA3C67FF12B1D19CCD43F32DDA905E96&q=" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search] "Start Page"="http://www.google.com" "Start Default_Page_URL"="http://www.google.com" "Default_Search_URL"="http://www.google.com" "Search Bar"="http://www.google.com" "Search Page"="http://www.google.com" "CustomizeSearch"="http://www.bing.com/search?q={searchTerms}" "SearchAssistant"="http://www.bing.com/search?q={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Start Page"="http://www.google.com" "Start Default_Page_URL"="http://www.google.com" "Search Bar"="http://www.google.com" "Search Page"="http://www.google.com" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs] "Tabs"="res://ieframe.dll/tabswelcome.htm" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "CustomizeSearch"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm" "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR" ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\358CA8E5BB5699C40AE9918B81151EC4 deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{6754D05B-CE55-3892-A77D-464C5C2E308D} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FA2A72AA-8FAE-2F29-8801-FA1F763D2A17} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\kmgeophbbmfgkjghdgfgelpipdoclljo deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\nbmafkdmkkckhggblphicnnhlgljnoje deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\ndgonipadfipmlmdfofnjnhhlgojnjdn deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0F44DC3A-6E62-4961-A14B-95323C512F9B}_is1 deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5E8AC853-65BB-4C99-A09E-19B81851E14C} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Mobogenie deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\358CA8E5BB5699C40AE9918B81151EC4 deleted successfully ==== Empty IE Cache ====================== C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Bart & Leen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Bart & Leen\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Luce\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Luce\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Administrator\AppData\Local\Mozilla\Firefox\Profiles\sztsgv0g.default\Cache emptied successfully C:\Users\Luce\AppData\Roaming\Mozilla\Firefox\Profiles\ukec3ixn.default\fastdial\cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Bart & Leen\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\Luce\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=2631 folders=320 226442830 bytes) ==== Empty Temp Folders ====================== C:\Users\Administrator\AppData\Local\temp emptied successfully C:\Users\Bart & Leen\AppData\Local\temp emptied successfully C:\Users\Default\AppData\Local\temp emptied successfully C:\Users\Default User\AppData\Local\temp emptied successfully C:\Users\Luce\AppData\Local\Temp will be emptied at reboot C:\Users\Public\AppData\Local\temp emptied successfully C:\Windows\system32\config\systemprofile\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Luce\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied C:\RECYCLER successfully emptied ==== EOF on ma 06/10/2014 at 22:31:51,92 ======================