Zoek.exe v5.0.0.0 Updated 23-04-2015 Tool run by Gido on zo 03-05-2015 at 13:44:31,80. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Gido\Downloads\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 3-5-2015 13:47:27 Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\PROGRA~2\Elaborate Bytes deleted successfully C:\PROGRA~2\FirstRowSportApp.com deleted successfully C:\PROGRA~2\MSXML 4.0 deleted successfully C:\PROGRA~2\Rockstar Games deleted successfully C:\PROGRA~2\SlySoft deleted successfully C:\PROGRA~2\COMMON~1\SWF Studio deleted successfully C:\Program Files\Google deleted successfully C:\PROGRA~3\Babylon deleted successfully C:\PROGRA~3\DAEMON Tools Pro deleted successfully C:\Users\Gido\AppData\Roaming\DAEMON Tools Pro deleted successfully C:\Users\Gido\AppData\Roaming\Publish Providers deleted successfully C:\Users\Gido\AppData\Roaming\TP deleted successfully C:\Users\Gido\AppData\Local\2K Games deleted successfully C:\Users\Gido\AppData\Local\Conduit deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3902010895-3865875327-1742431247-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_USERS\S-1-5-21-3902010895-3865875327-1742431247-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} deleted successfully HKEY_USERS\S-1-5-21-3902010895-3865875327-1742431247-1001\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully HKEY_USERS\S-1-5-21-3902010895-3865875327-1742431247-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-3902010895-3865875327-1742431247-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully HKEY_USERS\S-1-5-21-3902010895-3865875327-1742431247-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\Gido\AppData\Roaming\Mozilla\Firefox\Profiles\0 user.js not found ---- FireFox user.js and prefs.js backups ---- prefs_03-05-2015_1400_.backup ProfilePath: C:\Users\Gido\AppData\Roaming\Nvu\Profiles\rkt9vp51.default user.js not found ---- FireFox user.js and prefs.js backups ---- prefs_03-05-2015_1400_.backup ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] ==== Deleting Files \ Folders ====================== C:\PROGRA~2\Elaborate Bytes not found C:\PROGRA~2\FirstRowSportApp.com not found C:\PROGRA~2\Rockstar Games not found C:\PROGRA~2\SlySoft not found C:\Users\Gido\AppData\LocalLow\Conduit deleted C:\Users\Gido\AppData\Roaming\ParetoLogic deleted C:\Users\Gido\AppData\Roaming\DriverCure deleted C:\Users\Gido\AppData\Roaming\Babylon deleted C:\PROGRA~3\Partner deleted C:\PROGRA~3\ParetoLogic deleted C:\PROGRA~3\Package Cache deleted C:\Users\Gido\AppData\Local\CRE deleted C:\Users\Gido\Downloads\iLividSetupV1.exe deleted C:\Users\Gido\Downloads\SoftonicDownloader_voor_windows-live-movie-maker.exe deleted C:\Users\Gido\Downloads\SoftonicDownloader_voor_windows-movie-maker-2012.exe deleted C:\Users\Gido\Downloads\FirstRowSportApp_setup(47c42).exe deleted C:\Windows\SysNative\config\systemprofile\Searches deleted C:\Windows\SysWow64\searchplugins deleted C:\Windows\SysWow64\Extensions deleted "C:\Windows\tasks\AutoKMS.job" deleted "C:\Windows\AutoKMS.exe" deleted "C:\Windows\tasks\AutoKMSDaily.job" deleted "C:\Windows\AutoKMS.exe" deleted "C:\Windows\KMSEmulator.exe" deleted "C:\Users\Gido\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\freehdsport@freehdsport.tv.xpi" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\Gido\AppData\Local\Temp ==== 2015-05-03 08:10:44 C9889FA47FA63E6257B7A966C40BE286 43008 ----a-w- C:\Users\Gido\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpowkf5r.dll ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== ====== C:\Windows\Sysnative\drivers ===== ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2015-05-02 17:22:09 -------- d-----w- C:\Program Files\Speccy 2015-05-02 12:21:57 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== ======= C: ===== ====== C:\Users\Gido\AppData\Roaming ====== ====== C:\Users\Gido ====== 2015-05-02 18:14:07 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Gido\Downloads\RSITx64.exe ====== C: exe-files == 2015-05-03 08:46:54 B4605D865BF030CD5CEFCC3266A06C7F 41792592 ----a-w- C:\Program Files (x86)\Google\Update\Install\{86BE5F5F-F2AD-4515-8149-9FC439074EE2}\42.0.2311.135_chrome_installer.exe 2015-05-03 08:46:53 B4605D865BF030CD5CEFCC3266A06C7F 41792592 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\42.0.2311.135\42.0.2311.135_chrome_installer.exe 2015-05-02 18:14:36 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Gido.exe 2015-05-02 18:14:07 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Gido\Downloads\RSITx64.exe 2015-05-02 17:38:33 5CBF70FD73ED1498448C471F9672E17E 1089104 ----a-w- C:\Program Files (x86)\Google\Update\Install\{65204537-DBBF-49EA-BC07-B2493A84C1F8}\42.0.2311.135_42.0.2311.90_chrome_updater.exe 2015-05-02 17:38:33 5CBF70FD73ED1498448C471F9672E17E 1089104 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\42.0.2311.135\42.0.2311.135_42.0.2311.90_chrome_updater.exe 2015-04-27 08:13:59 516A5FCE06BB388499238A5F9286CB74 96768 ----a-w- C:\Windows\Temp\6D047807-C4B7-4F9E-8FED-25AAB15E50FF\DismHost.exe === C: other files == 2015-05-03 08:10:45 DE0983FE4B830699312D35A990B3AE1B 1945 ----a-w- C:\Users\Gido\AppData\Local\Temp\_MEI37082\resources\chrome_ext\nknebiagdodnminbdpflhpkgfpeijdbf_live.crx 2015-05-03 08:10:45 82F5C942549405F61A8808D0EA0FA9E2 25575 ----a-w- C:\Users\Gido\AppData\Local\Temp\_MEI37082\resources\chrome_ext\apdfllckaahabafndbhieahigkjlhalf_live.crx 2015-05-02 08:33:05 DE0983FE4B830699312D35A990B3AE1B 1945 ----a-w- C:\Users\Gido\AppData\Local\Temp\_MEI23922\resources\chrome_ext\nknebiagdodnminbdpflhpkgfpeijdbf_live.crx 2015-05-02 08:33:05 82F5C942549405F61A8808D0EA0FA9E2 25575 ----a-w- C:\Users\Gido\AppData\Local\Temp\_MEI23922\resources\chrome_ext\apdfllckaahabafndbhieahigkjlhalf_live.crx ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-3902010895-3865875327-1742431247-1001\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" "MediaGet2"="C:\Users\Gido\AppData\Local\MediaGet2\mediaget.exe --minimized" "MobileDocuments"="C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe" "ApplePhotoStreams"="C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" "iCloudServices"="C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" "GoogleDriveSync"="C:\Program Files (x86)\Google\Drive\googledrivesync.exe /autostart" "EADM"="C:\Program Files (x86)\Origin\Origin.exe -AutoStart" "uTorrent"="C:\Users\Gido\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" "OneDrive"="C:\Users\Gido\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CLMLServer"="C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" "NUSB3MON"="C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" "AdobeCS5.5ServiceManager"="C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe -launchedbylogin" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "BCSSync"="C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe /DelayServices" "PWRISOVM.EXE"="C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup" "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun" "amd_dc_opt"="C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe" "avgnt"="C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe /min" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime" "Avira Systray"="C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" "MediaGet2"="C:\Users\Gido\AppData\Local\MediaGet2\mediaget.exe --minimized" "MobileDocuments"="C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe" "ApplePhotoStreams"="C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" "iCloudServices"="C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe" "GoogleDriveSync"="C:\Program Files (x86)\Google\Drive\googledrivesync.exe /autostart" "EADM"="C:\Program Files (x86)\Origin\Origin.exe -AutoStart" "uTorrent"="C:\Users\Gido\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" "OneDrive"="C:\Users\Gido\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" "Logitech Download Assistant"="C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch" "XboxStat"="C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe silentrun" ==== Startup Folders ====================== 2015-03-10 18:23:36 1135 ----a-w- C:\Users\Gido\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk 2011-09-06 11:10:44 1243 ----a-w- C:\Users\Gido\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3 .lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [18-04-2015 12:06] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [17-10-2014 21:19] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [17-10-2014 21:19] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\AdobeAAMUpdater-1.0-Gido-PC-Gido" [C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\{4DF96E52-D9B1-43BD-9372-52A54491AA03}" [C:\Users\Gido\AppData\Roaming\Dropbox\bin\Dropbox.exe] "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Gido\AppData\Roaming\Nvu\Profiles\rkt9vp51.default - Undetermined - %ProfilePath%\extensions\installed-extensions.txt - Nvu default - %ProfilePath%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== ==== Chromium Look ====================== Google Chrome Version: 42.0.2311.135 (Possible outdated, latest Stable version: , Mac and Linux. A list of changes is available in the log.
) HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions bgnnidmnbdkmhfkjgdnngciimpdgohok - C:\Program Files (x86)\FirstRowSportApp.com\stv12.crx[] lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[14-07-2014 19:22] meinjhkhgaalhfbinmclpmjikccbplkf - C:\Users\Gido\AppData\Local\CRE\meinjhkhgaalhfbinmclpmjikccbplkf.crx[] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions apdfllckaahabafndbhieahigkjlhalf - C:\Users\Gido\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx[27-05-2014 18:28] lmjegmlicamnimmfhcmpkclmigmmcbeh - No path found[] meinjhkhgaalhfbinmclpmjikccbplkf - C:\Users\Gido\AppData\Local\CRE\meinjhkhgaalhfbinmclpmjikccbplkf.crx[] Google Drive - Gido\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf selector is not a valid CSS selector - Gido\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb Avira Browser Safety - Gido\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk Hola Better Internet - Gido\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio Bookmark Manager - Gido\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik Night Time In New York City - Gido\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnimonidkipnhnpgkhgliocfnnpgkhek Google Maps - Gido\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh Google Wallet - Gido\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Bitdefender QuickScan - Gido\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie ==== Chromium Startpages ====================== C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Preferences "startup_urls": [ "http://google.nl/" ] ==== Chromium Fix ====================== C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_alert.client.conduit.com_0.localstorage deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_alert.client.conduit.com_0.localstorage-journal deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_apps.conduit.com_0.localstorage deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_apps.conduit.com_0.localstorage-journal deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_groupon.conduitapps.com_0.localstorage deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_groupon.conduitapps.com_0.localstorage-journal deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage-journal deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_productivity3.ourtoolbar.com_0.localstorage deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_productivity3.ourtoolbar.com_0.localstorage-journal deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.lyricsfreak.com_0.localstorage deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.lyricsfreak.com_0.localstorage-journal deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_vacatures.trovit.nl_0.localstorage deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_vacatures.trovit.nl_0.localstorage-journal deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.ak.facebook.com_0.localstorage deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.ak.facebook.com_0.localstorage-journal deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.audienceinsights.net_0.localstorage deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.audienceinsights.net_0.localstorage-journal deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.castto.me_0.localstorage deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.castto.me_0.localstorage-journal deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_charting.vwdservices.com_0.localstorage deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_charting.vwdservices.com_0.localstorage-journal deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_immigrationcanadaservices.com_0.localstorage deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_immigrationcanadaservices.com_0.localstorage-journal deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.delta-search.com_0.localstorage deleted successfully C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.delta-search.com_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SPCB3E795F-DA21-460E-8E3F-056D755011F7&SSPV=" "Default_Page_URL"="http://www.aldi.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Unknown Url="Not_Found" {E5B56270-1B81-42F7-8C61-36B7F2703EB1} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7MDNC_nlNL442" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3902010895-3865875327-1742431247-1001\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\bgnnidmnbdkmhfkjgdnngciimpdgohok deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\meinjhkhgaalhfbinmclpmjikccbplkf deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\meinjhkhgaalhfbinmclpmjikccbplkf deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gido\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Gido\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gido\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gido\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\03H112M9 will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\Gido\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=64 folders=25 18417917 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Gido\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Gido\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== After Reboot ====================== ==== Deleting Files / Folders ====================== "C:\Users\Gido\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\03H112M9" not found "C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted ==== EOF on zo 03-05-2015 at 14:22:52,05 ======================