Zoek.exe v5.0.0.0 Updated 08-February-2015 Tool run by Rudi on ma 09/02/2015 at 20:09:13,83. Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Rudi\Downloads\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 9/02/2015 20:13:53 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~3\Validity deleted successfully C:\Users\Rudi\AppData\Local\PDFC deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{14D11F77-F745-44BC-A332-2976B641CF1E} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1530C90-CBD0-4764-8695-689B11F2E055} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2CBDC3E3-11FA-45A9-9FC2-E4AFE88040FB} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D963377-20A5-4968-B32B-E16ECB347F7} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{34AA03F6-C1E6-42E2-908F-383A9D2122B5} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{362D9E73-F17-4812-A437-80B717895E90} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{39761F82-BFA2-4267-BC25-FF85784C8490} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{46B647B-3077-49BE-A2E9-5CF1AC8A8283} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4769354A-ABFF-4FD7-AF2B-893BA7AB3F93} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4961628E-1EF6-421E-AAD3-252D42E7ACA1} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4AC55D4A-3180-4611-AC92-2FC4D5E1A35B} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{51CD78F1-C958-4AFE-AF71-1090378088A6} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6196E7CA-8FD9-4B2B-BD29-BE1FFCD2A12} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6977d7f0-230f-4cf2-b039-02bfe47595c0} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{757F2F07-14FA-4D87-B39F-B13B8BA678BA} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{75B80F3D-F895-45D8-AEE7-242D3BC2FF0} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7D34FDF5-7313-4CC6-A25B-6068B3C0E3BF} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8032F1D4-5906-4042-AC4-29A88CF05F7} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8485FF1E-8172-4BEA-BD6-FAC49566A5BF} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8578DD9B-650-4FCA-AD5D-E3558941B94} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{898E50A5-51F1-472B-A0D9-6040DEA5FDB2} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8A376EEF-21D8-4EE6-8768-94503DE97944} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8EA275F7-83EA-4F2F-9536-2E1B7FB0E245} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9B2BA8EA-4F5E-4F55-832E-B7C8F7FA6211} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9E90A425-372D-466B-A638-4B1526AC222} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9FC87D40-6449-4FC2-8DE1-7CCB9EC0737D} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2FDCB7D-941E-468B-9B2C-8C8DBE938159} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4008B9-29CD-40E6-AB77-A5B8D963926} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a60c5bc5-0080-42ba-8d61-ab300e74edad} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A6805AC6-28C5-4297-A027-F48D4157A67B} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC539EDF-6986-43DA-9D13-CF6636BD425E} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ACE3E127-8213-4247-B257-9A376FFE432} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B9FBBACD-E806-4375-8D70-FF3D9F24C50} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BE1D9C56-F5B3-403E-B8C2-E620F0ADBE9E} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C2ABC81B-65CA-45F9-810-D2B9EB6334BA} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C692CCBA-6E76-482B-82B-984EB03ECD55} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CA2AA15B-DBAC-48AE-9DEC-3E5DCB28418D} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CBC9F1E5-7512-494C-8862-45F1B72AD16} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CF8880D-10EC-4598-A293-F3563F0748D} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D5729281-C64F-4EB8-A57-1BB939F9FAF4} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB368675-C8D0-4FF7-9093-16B1E2D3DEBE} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DCA044B2-5FC7-4678-AAAB-A2324D425EA9} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e091f4c4-14fa-4cf9-91fe-a6adb1213c9e} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E41395AF-6426-4713-BEEE-925CE7BCC9F} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EB612C17-4C0F-451C-AF19-2F8684326FE3} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EB7ADC6-8912-472F-A74C-60158AD22BCD} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ED9B7883-8C67-44AB-88D-D6E4BE911379} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEA916A0-3553-464D-81E5-C2FED7AB2B2} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F34A94D7-E6BA-484A-AB33-7A4D5C3A20A0} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4542EA9-E2F-4ECA-87C8-70A553E43477} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F8C4B247-3585-401C-842D-9B21BD894C4} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fb4e516e-3d75-4831-acc5-f0118587f704} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fd1b8099-56a0-4615-b70d-af29b15d6b6c} deleted successfully HKEY_CLASSES_ROOT\CLSID\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Approved Extensions\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47} deleted successfully ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iSafeService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\iSafeService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iSafeKrnl deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\iSafeKrnl deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SmdmFService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SmdmFService deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\iSafeNetFilter deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\iSafeNetFilter deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\F06DEFF2-5B9C-490D-910F-35D3A91196222 deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\F06DEFF2-5B9C-490D-910F-35D3A91196222 deleted successfully ==== FireFox Fix ====================== ProfilePath: C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default user.js not found ---- Lines delta removed from prefs.js ---- user_pref("browser.newtab.url", "http://www.delta-homes.com/newtab/?type=nt&ts=1420117689&from=wpm12311&uid=ST9320423AS_5VH6D8DW"); user_pref("extensions.delta.admin", false); user_pref("extensions.delta.aflt", "babsst"); user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); user_pref("extensions.delta.autoRvrt", "false"); user_pref("extensions.delta.bbDpng", "8"); user_pref("extensions.delta.cntry", "BE"); user_pref("extensions.delta.dfltLng", "nl"); user_pref("extensions.delta.excTlbr", false); user_pref("extensions.delta.ffxUnstlRst", true); user_pref("extensions.delta.hdrMd5", "7E5E783EBF49FA7F5BC50F11F5B6B349"); user_pref("extensions.delta.id", "e663b1d700000000000090004e8b055f"); user_pref("extensions.delta.instlDay", "15977"); user_pref("extensions.delta.instlRef", "sst"); user_pref("extensions.delta.lastVrsnTs", "1.8.24.612:24:14"); user_pref("extensions.delta.newTab", false); user_pref("extensions.delta.prdct", "delta"); user_pref("extensions.delta.prtnrId", "delta"); user_pref("extensions.delta.rvrt", "false"); user_pref("extensions.delta.sg", "azb"); user_pref("extensions.delta.smplGrp", "none"); user_pref("extensions.delta.tlbrId", "base"); user_pref("extensions.delta.tlbrSrchUrl", ""); user_pref("extensions.delta.vrsn", "1.8.24.6"); user_pref("extensions.delta.vrsnTs", "1.8.24.612:24:14"); user_pref("extensions.delta.vrsni", "1.8.24.6"); user_pref("extensions.delta_i.babExt", ""); user_pref("extensions.delta_i.babTrack", "affID=119357&tsp=5020"); user_pref("extensions.delta_i.srcExt", "ss"); ---- Lines mixidj removed from prefs.js ---- user_pref("extensions.mixidj.admin", false); user_pref("extensions.mixidj.aflt", "babsst"); user_pref("extensions.mixidj.appId", "{A2773ED4-83BD-488A-A186-73590706C916}"); user_pref("extensions.mixidj.autoRvrt", "false"); user_pref("extensions.mixidj.babTrack", "affID=100547"); user_pref("extensions.mixidj.bbDpng", "23"); user_pref("extensions.mixidj.cntry", "BE"); user_pref("extensions.mixidj.dfltLng", "en"); user_pref("extensions.mixidj.excTlbr", false); user_pref("extensions.mixidj.ffxUnstlRst", false); user_pref("extensions.mixidj.hdrMd5", "418593451D00BCDF020778846D43F6DB"); user_pref("extensions.mixidj.id", "e663b1d700000000000090004e8b055f"); user_pref("extensions.mixidj.instlDay", "15850"); user_pref("extensions.mixidj.instlRef", "sst"); user_pref("extensions.mixidj.lastVrsnTs", "1.8.18.819:24:59"); user_pref("extensions.mixidj.newTab", false); user_pref("extensions.mixidj.prdct", "mixidj"); user_pref("extensions.mixidj.prtnrId", "mixidj"); user_pref("extensions.mixidj.rvrt", "false"); user_pref("extensions.mixidj.smplGrp", "netscomp"); user_pref("extensions.mixidj.tlbrId", "base"); user_pref("extensions.mixidj.tlbrSrchUrl", ""); user_pref("extensions.mixidj.vrsn", "1.8.18.8"); user_pref("extensions.mixidj.vrsni", "1.8.18.8"); user_pref("extensions.mixidj.vrsnTs", "1.8.18.819:24:59"); ---- Lines xpiState" removed from prefs.js ---- user_pref("extensions.xpiState", "{\"app-profile\":{\"detgdp@gmail.com\":{\"d\":\"C:\\\\Users\\\\Rudi\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\P ---- Lines Whilokii removed from prefs.js ---- user_pref("extensions.Whilokii.aul", "1384281550831"); user_pref("extensions.Whilokii.irl", true); user_pref("extensions.Whilokii.is", "isgiwhBE"); user_pref("extensions.Whilokii.ug", "78323aa8-d18f-402c-b239-ed37679fd245"); ---- Lines {336D0C35-8A85-403a-B9D2-65C292C39087} removed from prefs.js ---- user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.extensionFirstRun", false); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.lastExtensionVersion", "2.0.0.462"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_installer_name", "sg_6R8z4jeDip_active_MB168_MB169_UA-26924354-2_2012-07-15-15-46-37"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_product_name", "Web Assistant"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_product_version", "2.0.0.462"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_temp_installer_name", "sg_6R8z4jeDip_active_MB168_MB169_UA-26924354-2_2012-07-15-15-46-37 user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_toolbarID", "f25ffd201da44dd98805adb4795e84a7"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_dailyPing", "true|||1345992285246"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_debugMode", "not set"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_gtQueryParam", "UA-26924354-2"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_installedPing", "true|||8641342360026403"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_lastUpdate", "1345905883674|||8641345905883675"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_redirectQueryParam1", "MB168"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_redirectQueryParam2", "MB169"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_showtoaster", "not set"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_status", "inactive"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_toasterID", "not set"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.ScriptData_WSG_upn2", "6R8z4jeDip"); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.setdefaultsearch_2.0.0.462", false); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.setdnscatch_2.0.0.413", false); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.setdnscatch_2.0.0.462", false); user_pref("{336D0C35-8A85-403a-B9D2-65C292C39087}.sethomepage_2.0.0.462", false); ---- Lines {8E9E3331-D360-4f87-8803-52DE43566502} removed from prefs.js ---- user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.extensionFirstRun", false); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.lastExtensionVersion", "2.0.0.602"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_installer_name", "sg_6R8z4jeDip_active_MB168_MB169_UA-26924354-2_2012-07-15-15-46-37"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_product_name", "Web Assistant"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_product_version", "2.0.0.602"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_temp_installer_name", "sg_6R8z4jeDip_active_MB168_MB169_UA-26924354-2_2012-07-15-15-46-37 user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_toolbarID", "f25ffd201da44dd98805adb4795e84a7"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_dailyPing", "true|||1374676511419"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_debugMode", "not set"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_dialogVersion", "not set"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_geoRequest", "BE|||8641374414005918"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_gtQueryParam", "UA-26924354-2"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_inactive_by_user", "not set"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_installedPing", "true|||8641374414005084"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_kswitch", "not set"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_lastUpdate", "1374590111038|||8641374590111038"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_redirectQueryParam1", "MB168"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_redirectQueryParam2", "MB169"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_showDialog", "not set"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_showtoaster", "not set"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_ssl", "|||8641374414005083"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_status", "active|||8641374591175942"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_toasterID", "5|||8641374591144935"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_toolbar_query", "not set"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_uninstallDialog", "not set"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_WSG_upn2", "6R8z4jeDip"); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.setdefaultsearch_2.0.0.602", false); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.setdnscatch_2.0.0.413", false); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.setdnscatch_2.0.0.602", false); user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.sethomepage_2.0.0.602", false); ---- Lines search.net removed from prefs.js ---- user_pref("browser.search.defaultenginename", "default-search.net"); user_pref("browser.search.order.1", "default-search.net"); user_pref("browser.search.selectedEngine", "default-search.net"); user_pref("keyword.URL", "http://www.default-search.net/search?sid=476&aid=135&itype=a&ver=15005&tm=604&src=ds&p="); ---- Lines quick_start removed from prefs.js ---- user_pref("extensions.quick_start.enable_search1", false); user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false); ---- Lines Customized removed from prefs.js ---- user_pref("extensions.testpilot.alreadyCustomizedToolbar", true); ---- Lines offers removed from prefs.js ---- user_pref("extentions.webcake.defaultEnableAppsList", "layers/banner,layers/inline,layers/search,layers/shopping,newOffers/wc"); ---- Lines helperbar removed from prefs.js ---- user_pref("extensions.helperbar.backPageCapacity", 3); user_pref("extensions.helperbar.backPageCounter", 0); user_pref("extensions.helperbar.backPageDay", 12); user_pref("extensions.helperbar.backPageLastEvent", "1405015214403"); user_pref("extensions.helperbar.backPageMinInterval", 15); user_pref("extensions.helperbar.barcodeid", "144394"); user_pref("extensions.helperbar.countryiso", "be"); user_pref("extensions.helperbar.DockingPositionDown", false); user_pref("extensions.helperbar.downloadprovider", "onsf"); user_pref("extensions.helperbar.fromautoupdate", "false"); user_pref("extensions.helperbar.installationid", "85ef7fd3-074a-3a24-3ccb-94d2a6932e05"); user_pref("extensions.helperbar.installdate", "12/07/2014"); user_pref("extensions.helperbar.keepAliveLastevent", "1405187910"); user_pref("extensions.helperbar.lastExternalJsUpdate", "1407665998906"); user_pref("extensions.helperbar.publisher", "onsf"); user_pref("extensions.helperbar.SmartbarDisabled", false); user_pref("extensions.helperbar.SmartbarStateMinimaized", false); user_pref("extensions.helperbar.Visibility", false); ---- FireFox user.js and prefs.js backups ---- prefs_20150902_2038_.backup prefs_20152101_2025_.backup prefs_20152101_2219_.backup prefs_20152201_1920_.backup ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "SoftonicAssistant"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- ==== Deleting Files \ Folders ====================== C:\Users\Rudi\AppData\Local\Linkey deleted C:\Users\Rudi\AppData\Local\SoftonicAssistant deleted C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default\extensions\4sharedCopyLinks deleted C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default\extensions\detgdp@gmail.com deleted C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default\extensions\extension@linkeyproject.com deleted C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default\extensions\ftd@ftd.com deleted C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3} deleted C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} deleted C:\windows\syswow64\appdata deleted C:\PROGRA~2\Mozilla Firefox\browser\searchplugins\default-search.xml deleted C:\PROGRA~2\Pro Surveillance System(EN) deleted C:\diffpdf.exe deleted C:\User Data deleted C:\Users\Rudi\AppData\Roaming\FirefoxToolbar deleted C:\windows\sysWoW64\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Browse and Search the Internet.lnk deleted C:\PROGRA~3\UpdaterLog.txt deleted C:\PROGRA~3\smdmf deleted C:\PROGRA~3\Package Cache deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner deleted C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\Users\Rudi\Downloads\SoftonicDownloader_for_any-pdf-to-dwg-converter.exe deleted C:\Users\Rudi\Downloads\SoftonicDownloader_voor_free-mp3-cutter-and-editor.exe deleted C:\Users\Rudi\Downloads\SoftonicDownloader_voor_picasa.exe deleted C:\windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG SafeGuard toolbar deleted C:\windows\SysNative\config\systemprofile\Searches deleted C:\windows\SysWow64\searchplugins deleted C:\windows\SysWow64\Extensions deleted C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default\searchplugins\babylon.xml deleted C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default\searchplugins\default-search.xml deleted C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default\searchplugins\SafeFinder Search.xml deleted C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default\Invalidprefs.js deleted C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default\CT2422939 deleted C:\Users\Rudi\Desktop\Search.lnk deleted "C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default\extensions\firefoxdav@icloud.com" deleted "C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default\extensions\firefoxdav@icloud.com" deleted ==== Files Recently Created / Modified ====================== ====== C:\windows ==== ====== C:\Users\Rudi\AppData\Local\Temp ==== 2015-02-09 19:06:47 97511FE2CA09CC2E06C3CD6519C3494E 43008 ----a-w- C:\Users\Rudi\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpojsh0q.dll 2015-01-26 19:40:16 F48A9492D56C5E62ED8B8B8584D7B383 8784040 ----a-w- C:\Users\Rudi\AppData\Local\Temp\SettingsManagerSetup.exe 2015-01-26 19:40:16 4447723C9263C249C25E9EB93A759E52 1153144 ----a-w- C:\Users\Rudi\AppData\Local\Temp\SoftonicAssistant_v0-1-6.exe ====== Java Cache ===== ====== C:\windows\SysWOW64 ===== ====== C:\windows\SysWOW64\drivers ===== ====== C:\windows\Sysnative ===== ====== C:\windows\Sysnative\drivers ===== 2015-01-20 19:14:03 8EE84CC87D67CE4DE7AF907CCA559F52 52392 ----a-w- C:\windows\Sysnative\drivers\iSafeNetFilter.sys ====== C:\windows\Tasks ====== ====== C:\windows\Temp ====== ======= C:\Program Files ===== 2015-01-20 19:05:13 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2015-02-06 19:42:10 -------- d-----w- C:\PROGRA~2\Trend Micro 2015-01-26 19:32:17 -------- d-----w- C:\PROGRA~2\Visual Integrity 2015-01-21 18:27:52 -------- d-----w- C:\PROGRA~2\COMMON~1\Java 2015-01-20 19:13:57 -------- d-----w- C:\PROGRA~2\Elex-tech ======= C: ===== 2015-01-23 18:52:13 BDBCA9C17FA3262BB0C106CDB5F557F8 1349 ----a-w- C:\DelFix.txt ====== C:\Users\Rudi\AppData\Roaming ====== ====== C:\Users\Rudi ====== 2015-02-08 16:31:20 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Rudi\Downloads\RSITx64.exe 2015-01-26 19:40:16 87EEB5D853CC7532C3F1C476EFFFD613 4336051 ----a-w- C:\Users\Rudi\Desktop\pdfdwg.exe 2015-01-21 18:27:14 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-01-21 18:27:01 -------- d-----w- C:\ProgramData\Oracle ====== C: exe-files == 2015-02-08 16:31:20 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Rudi\Downloads\RSITx64.exe 2015-02-05 19:42:23 1F9A2717F6C6D3440B1F4A59FF96C708 1043024 ----a-w- C:\Program Files (x86)\Google\Update\Install\{F874BCC3-A8D1-4FD1-BBB7-49AD168D8CA0}\40.0.2214.111_40.0.2214.94_chrome_updater.exe 2015-02-05 19:42:23 1F9A2717F6C6D3440B1F4A59FF96C708 1043024 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\40.0.2214.111\40.0.2214.111_40.0.2214.94_chrome_updater.exe 2015-02-05 19:36:41 FD98434B6A06FE31A35E4BFBC827B290 52040 ----atw- C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleUpdateOnDemand.exe 2015-02-05 19:36:41 5F0A3AA68785C49454F56C9F2DDA0237 52040 ----atw- C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleUpdateWebPlugin.exe 2015-02-05 19:36:41 4C02536F4CA35911FB3EA5715F300C57 52040 ----atw- C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleUpdateBroker.exe 2015-02-05 19:36:40 7CA00A58AA808F4B9844C91845910377 880208 ----a-w- C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleUpdateSetup.exe 2015-02-05 19:36:36 F3B6470DA7CE34E559D3BA7365CC909C 115528 ----atw- C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleUpdateComRegisterShell64.exe 2015-02-05 19:36:36 83BB030C71C9727DCFB2737005772C4E 232264 ----atw- C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe 2015-02-05 19:36:36 323CFFFDAF253AC65CD194A101BE6231 287048 ----atw- C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe 2015-02-05 19:36:35 E1B44A75947137F4143308D566889837 107848 ----atw- C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleUpdate.exe 2015-02-05 19:36:32 7CA00A58AA808F4B9844C91845910377 880208 ----a-w- C:\Program Files (x86)\Google\Update\Install\{7562D120-B849-480C-8C29-99D09649D42F}\GoogleUpdateSetup.exe 2015-02-05 19:36:32 7CA00A58AA808F4B9844C91845910377 880208 ----a-w- C:\Program Files (x86)\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.26.9\GoogleUpdateSetup.exe === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" "iCloudServices"="C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" "GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run] "GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "File Sanitizer"="C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe" "IAStorIcon"="C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" "HP HD Webcam [Fixed]_Monitor"="C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe" "HPConnectionManager"="c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe" "HPQuickWebProxy"="c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe" "IFXSPMGT"="c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe /NotifyLogon" "Desktop Disc Tool"="C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" "QLBController"="C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "PDF Complete"="C:\Program Files (x86)\PDF Complete\pdfsty.exe" "lxdxmon.exe"="C:\Program Files (x86) (x86)\Lexmark 3600-4600 Series\lxdxmon.exe" "EzPrint"="C:\Program Files (x86) (x86)\Lexmark 3600-4600 Series\ezprint.exe" "Garmin Lifetime Updater"="C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized" "WinampAgent"="C:\Program Files (x86)\Winamp\winampa.exe" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime" "AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui" "BrMfcWnd"="C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN" "ControlCenter3"="C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" "iCloudServices"="C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" "GarminExpressTrayApp"="C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\Users\\Rudi\\AppData\\Local\\Linkey\\IEEXTE~1\\ietlb.dll " ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HPPowerAssistant"="C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden" "Broadcom Wireless Manager UI"="C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe" "IgfxTray"="C:\windows\system32\igfxtray.exe" "HotKeysCmds"="C:\windows\system32\hkcmd.exe" "Persistence"="C:\windows\system32\igfxpers.exe" "MfeEpePcMonitor"="C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe" "lxdxmon.exe"="C:\Program Files (x86)\Lexmark 3600-4600 Series\lxdxmon.exe" "EzPrint"="C:\Program Files (x86)\Lexmark 3600-4600 Series\ezprint.exe" "Cm106Sound"="C:\windows\syswow64\RunDll32.exe C:\windows\Syswow64\cm106.dll,CMICtrlWnd" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iTunesHelper] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="iTunesHelper" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\iTunes\\iTunesHelper.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="QuickTime Task" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\QuickTime\\QTTask.exe\" -atboottime" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^mw310.lnk] "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\mw310.lnk" "backup"="C:\\windows\\pss\\mw310.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\Mw310\\mw310.exe " "item"="mw310" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^Rudi^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LimeWire On Startup.lnk] "path"="C:\\Users\\Rudi\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk" "backup"="C:\\windows\\pss\\LimeWire On Startup.lnk.Startup" "backupExtension"=".Startup" "command"="C:\\PROGRA~2\\LimeWire\\LimeWire.exe -startup" "item"="LimeWire On Startup" ==== Startup Folders ====================== 2013-12-20 19:29:48 1135 ----a-w- C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk 2014-02-23 16:25:27 1193 ----a-w- C:\Users\Rudi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IconRestorer.lnk ==== Task Scheduler Jobs ====================== C:\windows\tasks\Adobe Flash Player Updater.job --a------ C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [14/01/2015 20:15] C:\windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [26/10/2014 13:24] C:\windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [26/10/2014 13:24] C:\windows\tasks\HPCeeScheduleForRudi.job --a------ C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [14/09/2010 07:15] C:\windows\tasks\SyncBack afbeeldingen.job --a------ C:\Program Files (x86)\2BrightSparks\SyncBack\SyncBack.exe [08/11/2010 14:42] C:\windows\tasks\SyncBack afbraak atelier server naar laptop.job --a------ [Undetermined Task] C:\windows\tasks\SyncBack cad tekeningen prive.job --a------ C:\Program Files (x86)\2BrightSparks\SyncBack\SyncBack.exe [08/11/2010 14:42] C:\windows\tasks\SyncBack documenten.job --a------ C:\Program Files (x86)\2BrightSparks\SyncBack\SyncBack.exe [08/11/2010 14:42] C:\windows\tasks\SyncBack muziek.job --a------ C:\Program Files (x86)\2BrightSparks\SyncBack\SyncBack.exe [08/11/2010 14:42] C:\windows\tasks\SyncBack mw310 van server naar laptop.job --a------ [Undetermined Task] C:\windows\tasks\SyncBack verkoop server naar laptop.job --a------ [Undetermined Task] ==== Other Scheduled Tasks ====================== "C:\windows\SysNative\tasks\Adobe Flash Player Updater" [C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\windows\SysNative\tasks\Apple Diagnostics" [C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe] "C:\windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\windows\SysNative\tasks\GarminUpdaterTask" [C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe] "C:\windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\windows\SysNative\tasks\HPCeeScheduleForRudi" [C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe] "C:\windows\SysNative\tasks\Installation App Launcher" ["C:\Program Files (x86)\Lexmark 3600-4600 Series\ezprint.exe"] "C:\windows\SysNative\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe] "C:\windows\SysNative\tasks\SyncBack afbeeldingen" [C:\Program Files (x86)\2BrightSparks\SyncBack\SyncBack.exe] "C:\windows\SysNative\tasks\SyncBack afbraak atelier server naar laptop" [C:\Program Files (x86)\2BrightSparks\SyncBack\SyncBack.exe] "C:\windows\SysNative\tasks\SyncBack documenten" [C:\Program Files (x86)\2BrightSparks\SyncBack\SyncBack.exe] "C:\windows\SysNative\tasks\SyncBack mw310 van server naar laptop" [C:\Program Files (x86)\2BrightSparks\SyncBack\SyncBack.exe] "C:\windows\SysNative\tasks\SyncBack verkoop server naar laptop" [C:\Program Files (x86)\2BrightSparks\SyncBack\SyncBack.exe] "C:\windows\SysNative\tasks\{7BF626DE-ABBF-4FB6-A554-EA9B8F99D048}" [G:\setup.exe] "C:\windows\SysNative\tasks\{F24F93F2-E18D-4D77-86D4-BA0E7961B095}" [G:\setup.exe] ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default user_pref("browser.startup.homepage", "http://www.google.be/"); user_pref("browser.search.defaulturl", "https://www.google.com/search"); user_pref("browser.search.defaultengine", "Google"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "detgdp@gmail.com"="C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default\extensions\detgdp@gmail.com" [] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default - Undetermined - detgdp@gmail.com - Undetermined - {195A3098-0BD5-4e90-AE22-BA1C540AFD1E} - NewTabURL - %ProfilePath%\extensions\newtaburl@sogame.cat.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Rudi\AppData\Roaming\Mozilla\Firefox\Profiles\i3e0fsb9.default B66B4D28D7D0C6322FF235C782CD6B76 - C:\windows\SysWOW64\npdeployJava1.dll - Java Deployment Toolkit 8.0.310.13 8560995C727974F27F2A1CE68909FEB9 - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll - Shockwave Flash 15E298B5EC5B89C5994A59863969D9FF - C:\windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System ==== Chromium Look ====================== Google Chrome Version: 40.0.2214.111 (Possible outdated, latest Stable version: 40.0.2214.94) HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[14/12/2014 11:54] Google Slides - Rudi\AppData\Local\Google\Chrome\User Data\default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek Google Docs - Rudi\AppData\Local\Google\Chrome\User Data\default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Rudi\AppData\Local\Google\Chrome\User Data\default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Rudi\AppData\Local\Google\Chrome\User Data\default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Rudi\AppData\Local\Google\Chrome\User Data\default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Sheets - Rudi\AppData\Local\Google\Chrome\User Data\default\Extensions\felcaaldnbdncclmgdcncolpebgiejap Avast Online Security - Rudi\AppData\Local\Google\Chrome\User Data\default\Extensions\gomekmidlodglbbmalcneegieacbdmki Google Wallet - Rudi\AppData\Local\Google\Chrome\User Data\default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Rudi\AppData\Local\Google\Chrome\User Data\default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Google Docs - C:\windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - C:\windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - C:\windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - C:\windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Select City - C:\windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo Google Wallet - C:\windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Extended Protection - C:\windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogfjmhfnldnajmfaofeiaepghjenbgjo Gmail - C:\windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chromium Startpages ====================== C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\default\Preferences "homepage": "http://www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=hp&from=wpm0226&uid=ST9320423AS_5VH6D8DW&ts=1393446614", "startup_urls": [ "http://www.delta-homes.com/?utm_source=b&utm_medium=wpm0226&utm_campaign=installer&utm_content=hp&from=wpm0226&uid=ST9320423AS_5VH6D8DW&ts=1393446614" ], ==== Chromium Fix ====================== C:\windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.default-search.net?sid=476&aid=135&itype=a&ver=15005&tm=604&src=hmp" "Search Page"="http://www.google.com" "Default_Page_URL"="http://www.delta-homes.com/?type=hp&ts=1420117689&from=wpm12311&uid=ST9320423AS_5VH6D8DW" "Default_Search_URL"="http://www.google.com" "Use Search Asst"="yes" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.delta-homes.com/?type=hp&ts=1420117689&from=wpm12311&uid=ST9320423AS_5VH6D8DW" "Search Page"="http://www.google.com" "Default_Page_URL"="http://www.delta-homes.com/?type=hp&ts=1420117689&from=wpm12311&uid=ST9320423AS_5VH6D8DW" "Default_Search_URL"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Start Page"="http://www.delta-homes.com/?type=hp&ts=1420117689&from=wpm12311&uid=ST9320423AS_5VH6D8DW" "Search Page"="http://www.google.com" "Default_Page_URL"="http://www.delta-homes.com/?type=hp&ts=1420117689&from=wpm12311&uid=ST9320423AS_5VH6D8DW" "Default_Search_URL"="http://www.google.com" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] @="http://www.google.com/search?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "SearchAssistant"="http://www.google.com" "Default_Search_URL"="http://www.google.com" "CustomizeSearch"="http://www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://www.google.com" "Use Search Asst"="no" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "CustomizeSearch"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm" "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {483830EE-A4CD-4b71-B0A3-3D82E62A6909} Unknown Url="Not_Found" {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} Microsoft (Bing) Url="http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Goo Url="http://www.google.com/search?q={sear" {D3DE1737-CF6F-451E-8365-CED37FBDB058} Google Url="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8" {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} Bing Url="http://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1} deleted successfully HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} deleted successfully HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} deleted successfully HKEY_CLASSES_ROOT\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{54739D49-AC03-4C57-9264-C5195596B3A1} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-1745162922-1544886962-622675663-1002\Software\Microsoft\Internet Explorer\Approved Extensions\{54739D49-AC03-4C57-9264-C5195596B3A1} deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\detgdp@gmail.com deleted successfully ==== Deleting Registry Keys ====================== HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Linkey deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Settings Manager deleted successfully HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\SoftonicAssistant deleted successfully HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\363FB0CBBA367FF4E81FEAD0F717B142 deleted successfully HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\95E0D778DBC66C3469F6F1B43A34EACE deleted successfully ==== Empty IE Cache ====================== C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Rudi\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Rudi\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\serviceprofiles\networkservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\Rudi\AppData\Local\Mozilla\Firefox\Profiles\i3e0fsb9.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Rudi\AppData\Local\Google\Chrome\User Data\default\Cache emptied successfully C:\windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=917 folders=202 318183968 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Rudi\AppData\Local\Temp will be emptied at reboot C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\windows\Temp successfully emptied C:\Users\Rudi\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Rudi\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted "C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found "C:\windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found "C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found ==== EOF on ma 09/02/2015 at 20:53:03,32 ======================