Zoek.exe v5.0.0.0 Updated 04-March-2015 Tool run by rita on do 05/03/2015 at 14:23:45,22. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\rita\AppData\Local\Microsoft\Windows\INetCache\IE\ZQ4OTBUG\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 5/03/2015 14:27:36 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\COMMON~1\Symantec Shared deleted successfully C:\Program Files\log deleted successfully C:\PROGRA~3\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} deleted successfully C:\Users\rita\AppData\Roaming\BRT deleted successfully C:\Users\Gast\AppData\Local\VirtualStore deleted successfully C:\Users\rita\AppData\Local\com deleted successfully C:\Users\rita\AppData\Local\CutePDF Writer deleted successfully C:\Users\rita\AppData\Local\Secunia PSI deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1287B4DD-4234-49BC-8F8-DB143796DE7} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1349F893-200C-4AAB-A7E9-15609C56BB8B} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{14960BE7-5715-4AD5-8888-FD6C2F4E44A6} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{15139461-4895-4B34-96A6-D4FAAA681C4} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{202EB8-C9B2-4327-9D44-1892CABFB67} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{20989C4D-1B61-4FB7-B2F8-D981A2EED} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{20EAC6FF-DFD-4F0B-9F45-31C6C52E132B} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{229D363D-9D58-48FF-AE3F-746198B8EC34} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{26820D63-294D-4D0E-93CE-D459F1EECB9A} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2a2c43b6-1b40-4228-ae9e-5a8e371c9667} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2F473EE8-4E44-420D-9DCE-25356959A72B} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2FB902BD-2BA6-43D6-8A6A-C07B7637E9F5} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{355521CE-CE50-4A85-BF91-D71FDDC7AFAF} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{366C7891-B6C7-47B3-AF7-CE48F5A9636B} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{376D6AA5-F522-44D8-B654-298C1AB3DBBB} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3AD8FBAD-6D7D-4065-993B-27DCA3AC06C} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3B368AE-C9BF-4CEA-BDFB-DC56C85BB1D} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D53E92-2DA2-48A4-B3AC-799D821D59C} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4254D384-7CC-4E8E-AB8A-9F4DE9625D38} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4267E615-7512-4CE3-8B74-1320D18D999} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{457BE1C5-6B-45FB-AC9D-CCB6D1DF2EC} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{46266B89-AFB9-48D9-9835-BC3B20178C95} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{478F57D3-68DC-41E1-A2EC-8AF4D0C21918} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{50C00B20-B430-45CF-907E-FD1FA3BD46E3} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{53144BFB-3DAB-498C-A926-9D658CF8F3B} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{566BE1B2-65E-4DEF-9625-6A69C8E3AE44} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62AA6FEB-2307-4609-8D3C-CB837521F3E8} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6378C2E6-C92D-469F-A9FC-FD92C64C21C} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{64EE0F1D-19C-45C3-8AB6-E09BAF518D54} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{72C636BD-B788-4229-A779-6EDCACEAA9C} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{783C9588-608B-4642-8335-3AD5B577F3D6} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79EB2ECB-8E48-41CF-92CA-AD3EA0C3BEE4} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7AA13AC2-8571-4C35-B79A-5EB398D8D} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7C5196AA-10F3-41C7-9C34-B6A4B3AE27AC} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7C78E0A-3917-42A6-B0A7-BCFDF5DD8FCE} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F2CC0DE-2A01-4843-A17D-91A67617DA19} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{895E4DE5-4669-4678-BA6E-B05CCE324B7E} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{94b4bd27-0742-49ae-8624-f267c786b426} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95D7E2E6-3B41-4A3A-B92E-3A1AEF8C8AE2} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9789AA87-B16-43CC-8331-CE87C6A14C6A} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A277B422-1145-41EE-8BFF-DDF670D5A61} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AA76D859-C953-4FA0-A75D-EBC2F7D2A9} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AD49DCDB-DAF3-4206-86C0-E0AD29A02966} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B0D16BFB-783C-493F-95EA-988B52492C2B} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B39AD932-30AD-4FC4-97F-5597DD4E8956} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B481C53D-EFF-4124-A172-FD16A34675D1} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B742BA6A-C580-4812-B45E-2269217495C} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B7A04DF5-BBB9-4972-AD65-8523F0716B30} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B7A36E47-D93E-4896-A366-F5221354EE9D} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BF417922-44B6-45F3-A91D-94396E8114D7} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BFA2E3B3-7906-482C-8DE3-FDB4FF8A447C} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C00D43F1-E187-453A-AD9C-51C1EF95DFC7} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C9122B33-9D3-4A4E-A07F-BC95FE2C2BD3} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CD4124FA-58E2-40B9-B964-3FE826FB4D60} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFBC3EF-DB6C-4752-B499-ED85838C289} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D110D536-3FF1-47B7-891-20F391C434A7} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D5A7CA35-93A4-42B8-ADA8-C12C7A4AB89E} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB5A66DF-F99-400D-9E94-B667CEB86E6} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DFB6041-1BBC-4586-B8E2-6BE1E7EC2EB} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E3631F1C-B940-4EFB-9B8B-B0ADC9472DCB} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E494DAFB-C8D9-4793-A63-4ADD988F82E0} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E872B79E-9C28-4CFD-A5EA-D65DA7B015FD} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EDA591EF-B988-4BB9-B019-6D5A9AE8A190} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F067ED71-71EE-4F38-998A-F9C24930973B} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F3603125-CC65-4BF7-AB32-93A2446CC8FB} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F48C349C-A045-480E-BF96-BB50E8F2797} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F606CE5-9893-46B7-B18F-2FBDBC8BBB4F} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FB5B7F58-E782-4C87-84CC-44CB2EF8EED7} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FD9853B8-FB5F-476E-8973-FCE53071C6} deleted successfully HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FDFC0F06-93C1-4E38-BDCA-9D61417C7390} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2a2c43b6-1b40-4228-ae9e-5a8e371c9667} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{94b4bd27-0742-49ae-8624-f267c786b426} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\rita\AppData\Roaming\Mozilla\Firefox\Profiles\fz89lp0l.default user.js not found ---- Lines BrowseFox removed from prefs.js ---- user_pref("extensions.BrowseFox.asul", "1395466370492"); user_pref("extensions.BrowseFox.aul", "1395466336650"); user_pref("extensions.BrowseFox.irl", true); user_pref("extensions.BrowseFox.is", "grbbfbe"); user_pref("extensions.BrowseFox.ug", "0d54592d-82ca-4b17-aa38-ddb77e35f682"); ---- Lines a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799 removed from prefs.js ---- user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.5c8764929678437cbd90994a5a82@ac863d978ade40948f4c7f15bb user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.5c8764929678437cbd90994a5a82@ac863d978ade40948f4c7f15bb user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.5c8764929678437cbd90994a5a82@ac863d978ade40948f4c7f15bb user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.5c8764929678437cbd90994a5a82@ac863d978ade40948f4c7f15bb user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.5c8764929678437cbd90994a5a82@ac863d978ade40948f4c7f15bb user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.5c8764929678437cbd90994a5a82@ac863d978ade40948f4c7f15bb user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.active", true); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.addressbar", "NA"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.addressbarenhanced", ""); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.asyncdb.was_copied", "true"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.asyncinternaldb.was_copied", "true"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.backgroundver", 1); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.certdomaininstaller", ""); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.changeprevious", false); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.cookie.InstallationTime.expiration", "Fri Feb 01 2030 0 user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.cookie.InstallationTime.value", "%221408907008%22"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00 user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.cookie.InstallerParams.value", "%7B%22source_id%22%3A%2 user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.description", "MediaPlayerEnhance Extension"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.domain", ""); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.enablesearch", false); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.homepage", ""); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.iframe", false); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.InstallationThankYouPage", true); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.InstallationTime", 1408907008); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.__defualt_browser__.expiration", "Fri Feb 01 user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.__defualt_browser__.value", "%22ch%22"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb._installer_additional_info.expiration", "Fri user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb._installer_additional_info.value", "%7B%22as user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.installer.expiration", "Fri Feb 01 2030 00:0 user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.installer.value", "%7B%22InstallerIdentifier user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.InstallerIdentifiers.expiration", "Fri Feb 0 user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.InstallerIdentifiers.value", "%7B%22installe user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.InstallerParams.expiration", "Fri Feb 01 203 user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.InstallerParams.value", "%7B%22source_id%22% user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.InstallerParamsCache.expiration", "Fri Feb 0 user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.InstallerParamsCache.value", "%7B%22source_i user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.InstallerUserIdentifiersCache.expiration", " user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.InstallerUserIdentifiersCache.value", "%7B%2 user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.monetization_plugin_bundledUrls.expiration", user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.monetization_plugin_bundledWithHash.expirati user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.monetization_plugin_bundledWithHash.value", user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.monetization_plugin_notBundledArr_.expiratio user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.monetization_plugin_notBundledArr_.value", " user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.monetization_plugin_regBundledWithSoftware.e user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.monetization_plugin_regBundledWithSoftware.v user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.Resources_appVer.expiration", "Fri Feb 01 20 user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.Resources_appVer.value", "107"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.Resources_lastVersion.expiration", "Fri Feb user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.Resources_lastVersion.value", "1"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.Resources_meta.value", "%7B%7D"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.Resources_nextCheck.expiration", "Tue Nov 18 user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.Resources_nextCheck.value", "true"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.Resources_queue.expiration", "Fri Feb 01 203 user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.internaldb.Resources_queue.value", "%7B%7D"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.lastDailyReport", "1416261276895"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.lastUpdate", "1416261274541"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.manifesturl", ""); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.name", "video MediaPlayers"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.newtab", ""); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.opensearch", ""); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.pluginsurl", "http://js.newonlinedatastack.com/plugin/a user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.pluginsversion", 103); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.publisher", "Freeven"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.searchstatus", 0); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.setnewtab", false); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.thankyou", ""); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.updateinterval", 360); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.61799.ver", 107); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.apps", "61799"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.bic", "1480996237e6da6778c809667b94dbcd"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.cid", 61799); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.firstrun", false); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.hadappinstalled", true); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.installationdate", 1408910108); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.installerAdditionalInfo", "{\"asw\":[32772, -2147483387, 1678 user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.modetype", "production"); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.reportInstall", true); user_pref("extensions.a5c8764929678437cbd90994a5a82ac863d978ade40948f4c7f15bb3c4com61799.statsDailyCounter", 9); ---- FireFox user.js and prefs.js backups ---- prefs_20150503_1633_.backup ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] ""=- [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] ""=- ==== Deleting Files \ Folders ====================== C:\PROGRA~3\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} not found C:\Users\rita\AppData\Roaming\Mozilla\Firefox\Profiles\fz89lp0l.default\extensions\abs@avira.com deleted C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 deleted C:\Users\rita\AppData\Roaming\Extensions deleted C:\Users\rita\AppData\Roaming\GoldenGate deleted C:\PROGRA~3\boost_interprocess deleted C:\PROGRA~3\Package Cache deleted C:\PROGRA~3\EmailNotifier deleted C:\Users\rita\AppData\Local\nsw6D6C.tmp deleted C:\Users\rita\AppData\Local\avgchrome deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\WINDOWS\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb deleted C:\WINDOWS\SysNative\config\systemprofile\Searches deleted C:\windows\SysNative\GroupPolicy\Machine deleted C:\windows\SysNative\GroupPolicy\User deleted C:\windows\SysNative\GroupPolicy\GPT.INI deleted C:\WINDOWS\Syswow64\GroupPolicy\gpt.ini deleted C:\WINDOWS\SysWow64\searchplugins deleted C:\WINDOWS\SysWow64\Extensions deleted C:\Users\rita\Desktop\Flvto Youtube Downloader.lnk deleted "C:\windows\Installer\5c01e.msi" deleted "C:\Users\rita\AppData\Roaming\hPWOpHY4EZVavTgM2DzrZ" deleted "C:\PROGRA~2\GUME109.tmp" not deleted "C:\PROGRA~2\Windows Multimedia Platform" not deleted "C:\PROGRA~2\GUME109.tmp" not deleted ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== ====== C:\Users\rita\AppData\Local\Temp ==== 2015-03-04 22:03:28 057631047016A448B842B96E872B132B 43008 ------w- C:\Users\rita\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpi7smmo.dll ====== Java Cache ===== 2015-02-10 15:08:00 725804308EA62BC7E5122E6DF92A6950 611 ----a-w- C:\Users\rita\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\6c389293-49fb21ac 2015-02-10 15:08:00 1B5C73F8D7BE78AC2EA40D4A00F19F28 474 ----a-w- C:\Users\rita\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19\6c389293-d80cfaf574bc6838c2a57396b99c2b1a4f2e1f1e7e2bbff262e483ecfb40393a-6.0.lap 2015-02-10 15:08:01 F832D3A8CF1721912CD282A0A4F6788C 2226 ----a-w- C:\Users\rita\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\727a7042-3845d403 2015-02-10 15:08:01 BBE051AFDCC0921D8E73C1F543E16B8A 16664 ----a-w- C:\Users\rita\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\6ee5f71f-68019e45 2015-02-10 15:08:19 82F5EBA9F5F412B4D05DF5C6DA15094D 1080608 ----a-w- C:\Users\rita\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\116d77e1-65d2328e 2015-02-10 15:08:01 CE187DB308F9F9B783C5E00150B45143 5127 ----a-w- C:\Users\rita\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\666e65ed-4323a459 ====== C:\WINDOWS\SysWOW64 ===== 2015-02-25 17:11:51 FB4299688A0D3A37687C015AC2B9922D 1374232 ----a-w- C:\WINDOWS\SysWOW64\D3DCompiler_36.dll 2015-02-25 17:11:51 D9158E78A368B08D9133043EB3058C12 444776 ----a-w- C:\WINDOWS\SysWOW64\d3dx10_36.dll 2015-02-25 17:11:50 44BFEC5C9C82A2EE9871D88FD3B9A0E2 3734536 ----a-w- C:\WINDOWS\SysWOW64\d3dx9_36.dll 2015-02-25 17:11:48 46EE68F04A75A1CCF40235EA6F1CBA05 267112 ----a-w- C:\WINDOWS\SysWOW64\xactengine2_9.dll 2015-02-25 17:11:47 F3764552E45880DC49B82F38699AA87C 444776 ----a-w- C:\WINDOWS\SysWOW64\d3dx10_35.dll 2015-02-25 17:11:47 5B441670A4F5F8BCCE76741902B8AF56 1358192 ----a-w- C:\WINDOWS\SysWOW64\D3DCompiler_35.dll 2015-02-25 17:11:46 3EF18B78D17C962F2B71AC1CB7757684 3727720 ----a-w- C:\WINDOWS\SysWOW64\d3dx9_35.dll 2015-02-25 17:11:44 F6A9FC2AD2F9111372B5AB3BBA3707EC 17928 ----a-w- C:\WINDOWS\SysWOW64\X3DAudio1_2.dll 2015-02-25 17:11:44 499210C45AFEAADEE8CF4DCF7D5E570B 266088 ----a-w- C:\WINDOWS\SysWOW64\xactengine2_8.dll 2015-02-25 17:11:42 75F206C195BBACA6EF28565B1C0CD75C 1124720 ----a-w- C:\WINDOWS\SysWOW64\D3DCompiler_34.dll 2015-02-25 17:11:42 5AA9987F2E62B56D7661B6901901F927 443752 ----a-w- C:\WINDOWS\SysWOW64\d3dx10_34.dll 2015-02-25 17:11:41 1CA939918ED1B930059B3A882DE6F648 3497832 ----a-w- C:\WINDOWS\SysWOW64\d3dx9_34.dll 2015-02-25 17:11:40 77F595DEE5FFACEA72B135B1FCE1312E 81768 ----a-w- C:\WINDOWS\SysWOW64\xinput1_3.dll 2015-02-25 17:11:38 7FEBB8CE2233CBAE738B16D42ED29674 261480 ----a-w- C:\WINDOWS\SysWOW64\xactengine2_7.dll 2015-02-25 17:11:37 FAE7E1D578C42A7C3D9D61A99D178BD5 1123696 ----a-w- C:\WINDOWS\SysWOW64\D3DCompiler_33.dll 2015-02-25 17:11:37 37A8171ACCF46A9C196054066C28827F 443752 ----a-w- C:\WINDOWS\SysWOW64\d3dx10_33.dll 2015-02-25 17:11:35 CDB1CD22BAFF21F48606B3C1A18B000B 3495784 ----a-w- C:\WINDOWS\SysWOW64\d3dx9_33.dll 2015-02-25 17:11:32 39000E033D39D19CCCE21AEAFCCE2476 255848 ----a-w- C:\WINDOWS\SysWOW64\xactengine2_6.dll 2015-02-25 17:11:30 86C93789E9006F1AC47ED9DD47D4C8A1 251672 ----a-w- C:\WINDOWS\SysWOW64\xactengine2_5.dll 2015-02-25 17:11:29 6F34F7405807DCBF0B9BF6811C94C6D9 440080 ----a-w- C:\WINDOWS\SysWOW64\d3dx10.dll 2015-02-25 17:11:27 26AF232140C88B42D92A88F2198EDF6A 3426072 ----a-w- C:\WINDOWS\SysWOW64\d3dx9_32.dll 2015-02-25 17:11:26 6550E1A0A7BE611592C31222FCB981FB 237848 ----a-w- C:\WINDOWS\SysWOW64\xactengine2_4.dll 2015-02-25 17:11:25 121B131EAA369D8F58DACC5C39A77D80 15128 ----a-w- C:\WINDOWS\SysWOW64\x3daudio1_1.dll 2015-02-25 17:11:24 797E24743937D67D69F28F2CF5052EE8 2414360 ----a-w- C:\WINDOWS\SysWOW64\d3dx9_31.dll 2015-02-25 17:11:22 69D841744B2BAE38FBB2D40A230A549C 236824 ----a-w- C:\WINDOWS\SysWOW64\xactengine2_3.dll 2015-02-25 17:11:21 33B62BE226934E1B01F5043870C70427 62744 ----a-w- C:\WINDOWS\SysWOW64\xinput1_2.dll 2015-02-25 17:11:20 5C4D3843B491C047B7A619901FBD2EC1 230168 ----a-w- C:\WINDOWS\SysWOW64\xactengine2_2.dll 2015-02-25 17:11:19 F1726346E583442541FE73429F8E9C10 62672 ----a-w- C:\WINDOWS\SysWOW64\xinput1_1.dll 2015-02-25 17:11:17 7C9952111F4C743B9F0D8B68B6ED93C9 229584 ----a-w- C:\WINDOWS\SysWOW64\xactengine2_1.dll 2015-02-25 17:11:11 E415862612E65F10D7D888443ECD7594 2388176 ----a-w- C:\WINDOWS\SysWOW64\d3dx9_30.dll 2015-02-25 17:11:09 4E961525CC7FF0E5D7DA19E170B7C14C 14032 ----a-w- C:\WINDOWS\SysWOW64\x3daudio1_0.dll 2015-02-25 17:11:09 2112FE0C46662D429347A7D7B49E3ECE 230096 ----a-w- C:\WINDOWS\SysWOW64\xactengine2_0.dll 2015-02-25 17:11:08 99F4FC172A5ACE36CF00AA7038D23F2C 2332368 ----a-w- C:\WINDOWS\SysWOW64\d3dx9_29.dll 2015-02-25 17:11:07 BE19B603DFBAA829EE5B7749B3BA97DB 2323664 ----a-w- C:\WINDOWS\SysWOW64\d3dx9_28.dll 2015-02-25 17:11:06 852EDC778A7A50077694F84D8E601234 2319568 ----a-w- C:\WINDOWS\SysWOW64\d3dx9_27.dll 2015-02-25 17:11:05 523AB607EEF81CC4D909E7FEBD8A788E 2297552 ----a-w- C:\WINDOWS\SysWOW64\d3dx9_26.dll 2015-02-25 17:11:02 5B48FE9D6686F0D54B26A005ACE24D1D 2337488 ----a-w- C:\WINDOWS\SysWOW64\d3dx9_25.dll 2015-02-25 17:11:00 BC831661963763AC4D504C5CABB1FDD9 2222800 ----a-w- C:\WINDOWS\SysWOW64\d3dx9_24.dll 2015-02-25 14:01:06 D4A564BABFF82F56E68835FBFDA7AB00 513488 ----a-w- C:\WINDOWS\SysWOW64\locale.nls ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== 2015-02-25 17:11:51 7299DF5CF81135934740211D9A946737 2006552 ----a-w- C:\WINDOWS\Sysnative\D3DCompiler_36.dll 2015-02-25 17:11:51 570FDAE7041775DE0C67747BB7081939 508264 ----a-w- C:\WINDOWS\Sysnative\d3dx10_36.dll 2015-02-25 17:11:50 BBB6C6833C30E323B41860D6DF61972D 5081608 ----a-w- C:\WINDOWS\Sysnative\d3dx9_36.dll 2015-02-25 17:11:48 A69C32C2BD01522A088D254342826866 411496 ----a-w- C:\WINDOWS\Sysnative\xactengine2_9.dll 2015-02-25 17:11:47 B21427EDF0449E92000FF497DAAF89C9 1985904 ----a-w- C:\WINDOWS\Sysnative\D3DCompiler_35.dll 2015-02-25 17:11:47 84116AA94672D623B95217648AE5B5B9 508264 ----a-w- C:\WINDOWS\Sysnative\d3dx10_35.dll 2015-02-25 17:11:46 1B3AF16A27D390096925576202A64037 5073256 ----a-w- C:\WINDOWS\Sysnative\d3dx9_35.dll 2015-02-25 17:11:44 FA485E76F94B7457767E372F47757733 409960 ----a-w- C:\WINDOWS\Sysnative\xactengine2_8.dll 2015-02-25 17:11:44 BC78D5328541410510DDE06B9FA92024 21000 ----a-w- C:\WINDOWS\Sysnative\X3DAudio1_2.dll 2015-02-25 17:11:42 9D9407F52B8E24E99358D9944B0D5FA3 1401200 ----a-w- C:\WINDOWS\Sysnative\D3DCompiler_34.dll 2015-02-25 17:11:42 1ED4E7A82BD5C7DEED082F00E63BB7A0 506728 ----a-w- C:\WINDOWS\Sysnative\d3dx10_34.dll 2015-02-25 17:11:41 AE5D5439525B4A4CBF206058D493685D 4496232 ----a-w- C:\WINDOWS\Sysnative\d3dx9_34.dll 2015-02-25 17:11:40 BFB3091B167550EC6E6454813D3DB244 107368 ----a-w- C:\WINDOWS\Sysnative\xinput1_3.dll 2015-02-25 17:11:38 8C970509E0AE10061E3ED6D51E34FEB9 403304 ----a-w- C:\WINDOWS\Sysnative\xactengine2_7.dll 2015-02-25 17:11:37 839C3921005BB41D441E3752C74F2292 506728 ----a-w- C:\WINDOWS\Sysnative\d3dx10_33.dll 2015-02-25 17:11:37 3EBF620536A13CA343E52ECA4F0DE7F8 1400176 ----a-w- C:\WINDOWS\Sysnative\D3DCompiler_33.dll 2015-02-25 17:11:35 3172C3CAC8EA7CA1B5D5AF6699C037D6 4494184 ----a-w- C:\WINDOWS\Sysnative\d3dx9_33.dll 2015-02-25 17:11:32 4837A54574A6105D404A8560984B93DD 393576 ----a-w- C:\WINDOWS\Sysnative\xactengine2_6.dll 2015-02-25 17:11:30 398FF46FF7354FED2F0F1AECDB546866 390424 ----a-w- C:\WINDOWS\Sysnative\xactengine2_5.dll 2015-02-25 17:11:29 8251826F04BA0822D08AD9B92C65A3D5 469264 ----a-w- C:\WINDOWS\Sysnative\d3dx10.dll 2015-02-25 17:11:27 A4DDFE5DC4E73D1FED9B1B3A3D885612 4398360 ----a-w- C:\WINDOWS\Sysnative\d3dx9_32.dll 2015-02-25 17:11:26 58BB51253427A834A8807B9245CC5965 364824 ----a-w- C:\WINDOWS\Sysnative\xactengine2_4.dll 2015-02-25 17:11:25 489E5B8BB1BD1028FF1C798EAAEC65E4 17688 ----a-w- C:\WINDOWS\Sysnative\x3daudio1_1.dll 2015-02-25 17:11:24 FAAA0BB9CD2905B25334132E5BA093EB 3977496 ----a-w- C:\WINDOWS\Sysnative\d3dx9_31.dll 2015-02-25 17:11:22 0396D2A98B0CCD4419B572EBF618E81E 363288 ----a-w- C:\WINDOWS\Sysnative\xactengine2_3.dll 2015-02-25 17:11:21 06F15D3CB1AE0EAFA50F595B3FF8D9F5 83736 ----a-w- C:\WINDOWS\Sysnative\xinput1_2.dll 2015-02-25 17:11:20 DC5A914C34EB12056531777D4DD0F44E 354072 ----a-w- C:\WINDOWS\Sysnative\xactengine2_2.dll 2015-02-25 17:11:19 6F9D3289D8B166E478AFFF9EFA92C42C 83664 ----a-w- C:\WINDOWS\Sysnative\xinput1_1.dll 2015-02-25 17:11:17 0CC809422AB40974DFF8078392E4D507 352464 ----a-w- C:\WINDOWS\Sysnative\xactengine2_1.dll 2015-02-25 17:11:11 E09A9CF383ACF4A28038561E62277377 3927248 ----a-w- C:\WINDOWS\Sysnative\d3dx9_30.dll 2015-02-25 17:11:09 F77D5AB654881E683CFF6650916C424E 16592 ----a-w- C:\WINDOWS\Sysnative\x3daudio1_0.dll 2015-02-25 17:11:09 CE5753F9A27837259EB52F3F47F39593 355536 ----a-w- C:\WINDOWS\Sysnative\xactengine2_0.dll 2015-02-25 17:11:08 68B35CBDB4A8CC424718BBCC894FEEEA 3830992 ----a-w- C:\WINDOWS\Sysnative\d3dx9_29.dll 2015-02-25 17:11:07 88BAC8306D4EC79A82B1FFA17DC8CF4A 3815120 ----a-w- C:\WINDOWS\Sysnative\d3dx9_28.dll 2015-02-25 17:11:06 914C3237E4D145A18DCD1D0D4C8659E1 3807440 ----a-w- C:\WINDOWS\Sysnative\d3dx9_27.dll 2015-02-25 17:11:05 44F5C5E27D6825E4E62420BC29B8B533 3767504 ----a-w- C:\WINDOWS\Sysnative\d3dx9_26.dll 2015-02-25 17:11:02 4C56E7C5B2A61353E534C7D15D05856D 3823312 ----a-w- C:\WINDOWS\Sysnative\d3dx9_25.dll 2015-02-25 17:11:00 B165DF72E13E6AF74D47013504319921 3544272 ----a-w- C:\WINDOWS\Sysnative\d3dx9_24.dll 2015-02-25 14:01:06 D4A564BABFF82F56E68835FBFDA7AB00 513488 ----a-w- C:\WINDOWS\Sysnative\locale.nls ====== C:\WINDOWS\Sysnative\drivers ===== 2015-02-11 10:17:32 3930E508DDA46C1FF68FD963F350AA0A 563504 ----a-w- C:\WINDOWS\Sysnative\drivers\cng.sys 2015-02-11 10:17:32 15C8C65CEA018C02EA0F648448C491C5 177984 ----a-w- C:\WINDOWS\Sysnative\drivers\ksecpkg.sys ====== C:\WINDOWS\Tasks ====== 2015-02-09 13:42:18 C5BB86D58668D823D3BA337B618622A7 3542 ----a-w- C:\WINDOWS\Sysnative\Tasks\HP AR Program Upload - 5e38dde98352466ea013aa9342be81b3dcd70564e02d46149edde24b9c2a6d66 ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2015-02-26 13:23:25 -------- d-----w- C:\Program Files\Adblock Plus for IE 2015-02-07 12:24:27 -------- d-----w- C:\Program Files\iPod 2015-02-07 12:24:12 -------- d-----w- C:\Program Files\iTunes ======= C:\PROGRA~2 ===== 2015-02-07 12:24:28 -------- d-----w- C:\PROGRA~2\iTunes ======= C: ===== ====== C:\Users\rita\AppData\Roaming ====== 2015-02-26 13:23:26 -------- d-----w- C:\Users\rita\AppData\Locallow\Adblock Plus for IE 2015-02-10 15:08:31 -------- d-----w- C:\Users\rita\AppData\Locallow\Unity 2015-02-10 15:08:31 -------- d-----w- C:\Users\rita\AppData\Local\Unity 2015-02-08 16:03:39 -------- d-----w- C:\Users\rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP 2015-02-08 16:03:31 -------- d-----w- C:\Users\rita\AppData\Roaming\HP Photo Creations 2015-02-07 12:16:03 -------- d-----w- C:\WINDOWS\SysNative\config\systemprofile\AppData\Roaming\Apple Computer 2015-02-04 11:57:35 -------- d-----w- C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Google ====== C:\Users\rita ====== 2015-03-05 14:04:58 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\winhttp 2015-02-28 12:35:13 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud 2015-02-28 12:26:23 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-02-04 10:26:16 -------- d-----w- C:\Users\rita\Tracing ====== C: exe-files == 2015-03-04 18:02:57 78206B34BD050DB564BF5B4B8C697925 1617224 ----a-w- C:\Program Files (x86)\Google\Google Toolbar\Component\SearchWithGoogleUpdate_6F4EEAE8D7FCDAD8.exe 2015-03-04 18:02:55 327C893AA5966AC436CA275F8D64C8C0 1072072 ----a-w- C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarManager_BA9226F4C70BECC2.exe 2015-03-04 18:02:23 D15EE16B871FE911D8D7C91FD5F57EBA 532312 ----a-w- C:\Program Files (x86)\Google\Update\Install\{7283531A-0340-4141-A9A7-774ABD7D3A21}\GoogleToolbarInstaller_updater_signed.exe 2015-03-04 18:02:23 D15EE16B871FE911D8D7C91FD5F57EBA 532312 ----a-w- C:\Program Files (x86)\Google\Update\Download\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\7.5.6227.252\GoogleToolbarInstaller_updater_signed.exe === C: other files == 2015-03-04 14:58:11 2DD63DBA58D76D3B500EEC1EF77B97EC 43392 ----a-w- C:\drivers\apg8201z.sys 2015-03-04 14:58:11 0F39961D10D4DE80C95BE441E42D9C23 50688 ----a-w- C:\drivers\apg8201zx64.sys 2015-03-04 14:58:10 888DFE4137F626CEA9CCE3BD47941B64 44672 ----a-w- C:\drivers\a38usbx64.sys 2015-03-04 14:58:10 8378A77DFAF832A7ACBE90F59066FF9A 14080 ----a-w- C:\drivers\acr38svr.sys 2015-03-04 14:58:10 5F92E1E98EC2F4E6FE13D19AA3E24AD7 37632 ----a-w- C:\drivers\a38usb.sys 2015-03-04 14:58:10 0FA03F53C0A635513F34B3D85BA1D361 17674 ----a-w- C:\drivers\a38usb98.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Windows\CurrentVersion\Run] "Facebook Update"="C:\Users\rita\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "HP Officejet 4620 series (NET)"="C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe -deviceID TH38P140FY05S1:NW -scfn HP Officejet 4620 series (NET) -AutoStart 1" "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" "Flvto Youtube Downloader"="C:\Users\rita\AppData\Local\Flvto Youtube Downloader\FlvtoYoutubeDownloader.exe /minimize" "NokiaSuite.exe"="C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe MSRun" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "avgnt"="C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe /min" "HP Software Update"="C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe" "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime" "SOSUAUI"="C:\Program Files (x86)\Malwarebytes Secure Backup\sosuploadagent.exe -showui" "SMessaging"="C:\Program Files (x86)\Malwarebytes Secure Backup\SMessaging.exe" "AccountCreatorRunner"="C:\Program Files (x86)\Malwarebytes Secure Backup\AccountCreatorRunner.exe" "Avira Systray"="C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe" "beid"="C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe /startup" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Facebook Update"="C:\Users\rita\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "HP Officejet 4620 series (NET)"="C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe -deviceID TH38P140FY05S1:NW -scfn HP Officejet 4620 series (NET) -AutoStart 1" "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" "Flvto Youtube Downloader"="C:\Users\rita\AppData\Local\Flvto Youtube Downloader\FlvtoYoutubeDownloader.exe /minimize" "NokiaSuite.exe"="C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="C:\Program Files\Apoint2K\Apoint.exe" "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" ==== Startup Folders ====================== 2014-10-20 15:29:39 1191 ----a-w- C:\Users\rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk 2015-02-03 12:30:48 1956 ----a-w- C:\Users\rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Inktwaarschuwingen controleren - .lnk 2015-02-25 17:16:56 1956 ----a-w- C:\Users\rita\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Inktwaarschuwingen controleren - HP Officejet 4620 series (netwerk).lnk 2014-04-04 14:58:17 1037 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BrytonBridge2.lnk 2014-11-24 14:49:03 1134 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\Adobe Flash Player Updater.job --a-------- C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [05/02/2015 18:12] C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-455634102-3971962441-1493714179-1001Core.job --a-------- C:\Users\rita\AppData\Local\Facebook\Update\FacebookUpdate.exe [19/10/2013 20:10] C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-455634102-3971962441-1493714179-1001UA.job --a-------- [Undetermined Task] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [10/07/2014 13:41] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [10/07/2014 13:41] C:\WINDOWS\tasks\Online Backup Update Notifier.job --a-------- C:\Program Files (x86)\Malwarebytes Secure Backup\SUpdateNotifier.exe [19/03/2014 14:25] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\WINDOWS\SysNative\tasks\Adobe Flash Player Updater" [C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\WINDOWS\SysNative\tasks\ALU" [C:\Program Files (x86)\Packard Bell\Live Updater\updater.exe] "C:\WINDOWS\SysNative\tasks\ALUAgent" [C:\Program Files (x86)\Packard Bell\Live Updater\liveupdater_agent.exe] "C:\WINDOWS\SysNative\tasks\AviraSpeedup" [C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe] "C:\WINDOWS\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\WINDOWS\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\BrowserChoice\browserchoice.exe] "C:\WINDOWS\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-455634102-3971962441-1493714179-1001Core" [C:\Users\rita\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\WINDOWS\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-455634102-3971962441-1493714179-1001UA" [C:\Users\rita\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - 5e38dde98352466ea013aa9342be81b3dcd70564e02d46149edde24b9c2a6d66" [C:\Program Files\HP\HP Officejet 4620 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP AR Program Upload - e3d50a65199b440ab997415d1e5e739e4065d4b0cb2e428ba1d966407de3867d" [C:\Program Files\HP\HP Officejet 4620 series\bin\HPRewards.exe] "C:\WINDOWS\SysNative\tasks\HP-Online updateprogramma" [C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe] "C:\WINDOWS\SysNative\tasks\HPCustParticipation HP Officejet 4620 series" ["C:\Program Files\HP\HP Officejet 4620 series\Bin\HPCustPartic.exe"] "C:\WINDOWS\SysNative\tasks\Java Update Scheduler" [C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe] "C:\WINDOWS\SysNative\tasks\Online Backup Update Notifier" [C:\Program Files (x86)\Malwarebytes Secure Backup\SUpdateNotifier.exe] "C:\WINDOWS\SysNative\tasks\Power Management" ["C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe"] "C:\WINDOWS\SysNative\tasks\User_Feed_Synchronization-{F7D9DAEC-2F1E-45EF-AB58-4774D849598F}" [C:\WINDOWS\system32\msfeedssync.exe] "C:\WINDOWS\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\rita\AppData\Roaming\Mozilla\Firefox\Profiles\fz89lp0l.default user_pref("browser.search.defaultengine", "Ask Search"); user_pref("browser.search.selectedEngine", "Bing "); user_pref("extensions.APN_TB.first-previous-keyword-url", ""); user_pref("extensions.ORJ-V7.my-keyword-url", "\"\""); user_pref("extensions.ORJ-V7.previous-keyword-url", "\"\""); user_pref("keyword.URL", "http://www.bing.com/search?FORM=U207DF&PC=U207&q="); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "{f8b7c7c7-4ef7-4ab2-8e68-0aae4045cd46}"="C:\Program Files (x86)\LyricsWOW\132.xpi" [] ==== Firefox Extensions ====================== ProfilePath: C:\Users\rita\AppData\Roaming\Mozilla\Firefox\Profiles\fz89lp0l.default - Undetermined - belgiumeid@eid.belgium.be - Undetermined - pagerank-client@koeniglich.ch - pagerankclientkoeniglichch - %ProfilePath%\extensions\pagerank-client@koeniglich.ch - Belgium eID - %ProfilePath%\extensions\belgiumeid@eid.belgium.be.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} - Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi ==== Firefox Plugins ====================== Profilepath: C:\Users\rita\AppData\Roaming\Mozilla\Firefox\Profiles\fz89lp0l.default 3CD19649B2C3023D65E67C056457A2BC - C:\Users\rita\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin 99F97C9FE748C37528C338A423577FCB - C:\Users\rita\AppData\Roaming\Mozilla\plugins\np-mswmp.dll - Microsoft® Windows Media Player Firefox Plugin ==== Chromium Look ====================== Google Chrome Version: 40.0.2214.115 (Up to date, latest Stable version: 40.0.2214.115) HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions nfmhcdakklnadpfeflffckpmjijiblia - C:\Program Files (x86)\LyricsWOW\132.crx[] Google Docs - rita\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - rita\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - rita\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - rita\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Avira SafeSearch - rita\AppData\Local\Google\Chrome\User Data\Default\Extensions\eglgfnfolcgijipffhlhbbnefdcbjbml Avira Browser Safety - rita\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk Google Wallet - rita\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - rita\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com/" "Search Page"="http://www.google.com" "Default_Page_URL"="http://www.google.com" "Search Bar"="http://www.google.com" "Use Search Asst"="yes" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "Default"="http://www.google.com" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://www.google.com" "SearchAssistant"="http://www.google.com" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://www.google.com/" "Use Search Asst"="no" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="http://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7" {DA6A79F6-5E4F-492C-BB27-EE9F60E3C6C8} Unknown Url="Not_Found" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\Microsoft\Internet Explorer\SearchScopes\{DA6A79F6-5E4F-492C-BB27-EE9F60E3C6C8} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-455634102-3971962441-1493714179-1001\Software\mozilla\Firefox\Extensions\{f8b7c7c7-4ef7-4ab2-8e68-0aae4045cd46} deleted successfully ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\203E62EEA6789D84098513925E9B9999 deleted successfully HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\nfmhcdakklnadpfeflffckpmjijiblia deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EE26E302-876A-48D9-9058-3129E5B99999} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\203E62EEA6789D84098513925E9B9999 deleted successfully ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\rita\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\rita\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\rita\AppData\Local\Microsoft\Windows\INetCache\IE\C90PSZRP will be deleted at reboot C:\Users\rita\AppData\Local\Microsoft\Windows\INetCache\IE\ZQ4OTBUG will be deleted at reboot C:\Users\rita\AppData\Local\Microsoft\Windows\INetCache\Low\IE\44S9P8LA will be deleted at reboot C:\Users\rita\AppData\Local\Microsoft\Windows\INetCache\Low\IE\8QAJGDRV will be deleted at reboot C:\Users\rita\AppData\Local\Microsoft\Windows\INetCache\Low\IE\ILNERYJ2 will be deleted at reboot C:\Users\rita\AppData\Local\Microsoft\Windows\INetCache\Low\IE\R5DRSSDS will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\rita\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=944 folders=205 175148509 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Gast\AppData\Local\Temp emptied successfully C:\Users\rita\AppData\Local\Temp will be emptied at reboot C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\rita\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\PROGRA~2\GUME109.tmp" not found "C:\PROGRA~2\Windows Multimedia Platform" not found "C:\PROGRA~2\GUME109.tmp" not found "C:\Users\rita\AppData\Local\Microsoft\Windows\INetCache\IE\C90PSZRP" not found "C:\Users\rita\AppData\Local\Microsoft\Windows\INetCache\IE\ZQ4OTBUG" not found "C:\Users\rita\AppData\Local\Microsoft\Windows\INetCache\Low\IE\44S9P8LA" not found "C:\Users\rita\AppData\Local\Microsoft\Windows\INetCache\Low\IE\8QAJGDRV" not found "C:\Users\rita\AppData\Local\Microsoft\Windows\INetCache\Low\IE\ILNERYJ2" not found "C:\Users\rita\AppData\Local\Microsoft\Windows\INetCache\Low\IE\R5DRSSDS" not found "C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted ==== EOF on do 05/03/2015 at 17:06:59,50 ======================