Zoek.exe v5.0.0.1 Updated 27-December-2015 Tool run by Merino on wo 30-12-2015 at 14:03:42,73. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Merino\Desktop\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 30-12-2015 14:05:59 Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\Users\Merino\AppData\Roaming\Publish Providers deleted successfully C:\Users\Merino\AppData\Local\Samsung deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Installed Programs ====================== æTorrent ActiveCheck component for HP Active Support Library Adobe Acrobat Reader DC - Nederlands Adobe AIR Adobe Flash Player 20 NPAPI Adobe Help Manager Adobe InDesign CC 2014 Adobe Photoshop CC 2015 Adobe Premiere Pro CS6 Adobe Refresh Manager Atheros Driver Installation Program ATI Catalyst Install Manager Audacity 2.1.1 AVG AVG 2016 AVG PC TuneUp AVG Protection Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center Graphics Previews Vista Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-core-static ccc-utility64 CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish DAEMON Tools Lite Dropbox Dropbox Update Helper DVD Menu Pack for HP MediaSmart Video ESU for Microsoft Windows 7 FMW 1 Free WMA to MP3 Converter 1.16 Glary Utilities PRO 5.38 Google Chrome Google Update Helper HP 3D DriveGuard HP Customer Experience Enhancements HP DVB-T TV Tuner 8.0.64.43 HP MediaSmart DVD HP MediaSmart Internet TV HP MediaSmart Movies and TV HP MediaSmart Music HP MediaSmart Photo HP MediaSmart SmartMenu HP MediaSmart Webcam HP Quick Launch HP Software Framework HP Support Assistant HP Wireless Assistant HPAsset component for HP Active Support Library IDT Audio Intel(R) Management Engine Components Intel(R) Rapid Storage Technology Intel(R) Turbo Boost Technology Driver LightScribe System Software Microsoft .NET Framework 4.5.2 Microsoft .NET Framework 4.5.2 (Nederlands) Microsoft .NET Framework 4.5.2 (NLD) Microsoft Application Error Reporting Microsoft Office Professional Plus 2016 - en-us Microsoft OneDrive Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 Microsoft_VC80_CRT_x86 Microsoft_VC90_CRT_x86 Movie Theme Pack for HP MediaSmart Video MSVCRT Redists MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Office 16 Click-to-Run Extensibility Component Office 16 Click-to-Run Licensing Component Office 16 Click-to-Run Localization Component PX Profile Update Realtek Ethernet Controller Driver For Windows 7 Realtek USB 2.0 Card Reader Recovery Manager Samsung Kies3 Security Update for Microsoft .NET Framework 4.5.2 (KB2972107) Security Update for Microsoft .NET Framework 4.5.2 (KB2972216) Security Update for Microsoft .NET Framework 4.5.2 (KB2978128) Security Update for Microsoft .NET Framework 4.5.2 (KB3023224) Security Update for Microsoft .NET Framework 4.5.2 (KB3035490) Security Update for Microsoft .NET Framework 4.5.2 (KB3037581) Security Update for Microsoft .NET Framework 4.5.2 (KB3074230) Security Update for Microsoft .NET Framework 4.5.2 (KB3074550) Security Update for Microsoft .NET Framework 4.5.2 (KB3097996) Security Update for Microsoft .NET Framework 4.5.2 (KB3098781) Spotify Synaptics Pointing Device Driver Vegas Pro 12.0 (64-bit) Visual Studio 2012 x64 Redistributables Visual Studio 2012 x86 Redistributables VLC media player WinRAR 5.20 (32-bit) x264vfw - H.264/MPEG-4 AVC codec (remove only) ==== Running Processes ====================== C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe C:\Users\Merino\AppData\Roaming\Spotify\SpotifyWebHelper.exe C:\Program Files (x86)\AVG\Framework\Common\avguix.exe C:\Program Files (x86)\AVG\Av\avgui.exe C:\Program Files (x86)\Dropbox\Client\Dropbox.exe C:\Windows\SysWOW64\ctfmon.exe C:\Program Files (x86)\Glary Utilities 5\Integrator.exe C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe C:\Users\Merino\Desktop\zoek.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TuneUp.UtilitiesSvc deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TuneUp.UtilitiesSvc deleted successfully ==== Deleting Files \ Folders ====================== "C:\Windows\zoek-delete.exe" not found C:\Users\Merino\AppData\Roaming\TuneUp Software deleted C:\PROGRA~3\Package Cache deleted "C:\DelFix.txt" deleted "C:\Program Files (x86)\AVG\AVG PC TuneUp\html.dat" not deleted "C:\Program Files (x86)\AVG\AVG PC TuneUp\tuavgx.dll" deleted "C:\Program Files (x86)\AVG\AVG PC TuneUp\tuneup_nl.lng" deleted "C:\Program Files (x86)\AVG\AVG PC TuneUp\tuuix.dll" deleted "C:\Program Files (x86)\AVG\AVG PC TuneUp" not deleted ==== System Specs ====================== Windows: Windows 7 Home Premium Edition (64-bit) Service Pack 1 (Build 7601) Memory (RAM): 2934 MB CPU Info: Intel(R) Pentium(R) CPU P6000 @ 1.87GHz CPU Speed: 1908,5 MHz Sound Card: Luidsprekers en koptelefoons (I | Onafhankelijke koptelefoons (ID | Display Adapters: Intel(R) Graphics Media Accelerator HD | Intel(R) Graphics Media Accelerator HD | ATI Mobility Radeon HD 5470 | ATI Mobility Radeon HD 5470 | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver Monitors: 1x; Algemeen PnP-beeldscherm | Screen Resolution: 1366 X 768 - 32 bit Network: Network Present Network Adapters: Atheros AR9285 802.11b/g/n WiFi Adapter CD / DVD Drives: 1x (F: | ) F: hp DVDRAM GT31L Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 5 Button Wheel Mouse Present Hard Disks: C: 276,1GB | D: 21,7GB | E: 99,3MB Hard Disks - Free: C: 81,7GB | D: 3,1GB | E: 90,3MB Manufacturer *: Hewlett-Packard BIOS Info: AT/AT COMPATIBLE | 06/22/10 | HPQOEM - 1 Time Zone: West-Europa (standaardtijd) Motherboard *: Hewlett-Packard 144A Country: Nederland Language: NLD ==== System Specs (Software) ====================== AV: AVG AntiVirus Free Edition *Disabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: AVG AntiVirus Free Edition *Disabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE} Default Browser: Google Chrome 47.0.2526.106 Internet Explorer Version: 11.0.9600.18124 Google Chrome version: 47.0.2526.106 Adobe Reader version: 15.9.20077.160923 Flash Player version: 20.0.0.267 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2015-12-28 21:53:47 D1E75542EC8D1B4851765A57AC63618E 1908 ----a-w- C:\Windows\diagwrn.xml 2015-12-28 21:53:47 02D3219818501F8912E2EE28F17A6232 2827 ----a-w- C:\Windows\diagerr.xml ====== C:\Users\Merino\AppData\Local\Temp ==== 2015-12-22 15:47:49 6DE5C66E434A9C1729575763D891C6C2 568832 ----a-w- C:\Users\Merino\AppData\Local\Temp\{E67A3ED5-E023-479A-A91F-4955111C104B}\msvcp90.dll 2015-12-22 15:47:48 E7D91D008FE76423962B91C43C88E4EB 655872 ----a-w- C:\Users\Merino\AppData\Local\Temp\{E67A3ED5-E023-479A-A91F-4955111C104B}\msvcr90.dll 2015-12-22 15:47:48 DA625B41B36D22E26FED7DAB0008E80F 327680 ----a-w- C:\Users\Merino\AppData\Local\Temp\{E67A3ED5-E023-479A-A91F-4955111C104B}\Kies2RemoveAll.exe 2015-12-22 15:47:48 D1CFCB3D64FBCC9B79E2A2892A032F8F 207872 ----a-w- C:\Users\Merino\AppData\Local\Temp\{E67A3ED5-E023-479A-A91F-4955111C104B}\MSSetupAddinDllForVista.dll 2015-12-22 15:47:48 CCD4FA08B11E3FE547479F94B120584E 1746944 ----a-w- C:\Users\Merino\AppData\Local\Temp\{E67A3ED5-E023-479A-A91F-4955111C104B}\KiesProgressDialog.dll 2015-12-22 15:47:48 C49DC5E35D0A847D7D94351B941BB1B9 214016 ----a-w- C:\Users\Merino\AppData\Local\Temp\{E67A3ED5-E023-479A-A91F-4955111C104B}\WriteDescExecuteFileName.exe 2015-12-22 15:47:48 AF21471072A837998506122CBBC1D26A 65536 ----a-w- C:\Users\Merino\AppData\Local\Temp\{E67A3ED5-E023-479A-A91F-4955111C104B}\Execute2App.exe 2015-12-22 15:47:48 87D31ACAE8AD8DBE45316217B3342A4E 468480 ----a-w- C:\Users\Merino\AppData\Local\Temp\{E67A3ED5-E023-479A-A91F-4955111C104B}\MSSetupAddinDll.dll 2015-12-22 15:47:48 7845C64F6EB3CE397CDDEFF7A2627697 8704 ----a-w- C:\Users\Merino\AppData\Local\Temp\{E67A3ED5-E023-479A-A91F-4955111C104B}\BrowseFolderDll.dll 2015-12-22 15:47:47 95C0E4F3732CD63795D620F958F0DE37 1193984 ----a-w- C:\Users\Merino\AppData\Local\Temp\{E67A3ED5-E023-479A-A91F-4955111C104B}\setup.exe 2015-12-22 15:47:47 8AC078212DE9D00591C55E6F7B61AFF0 286536 ----a-w- C:\Users\Merino\AppData\Local\Temp\{E67A3ED5-E023-479A-A91F-4955111C104B}\ISRT.dll 2015-12-22 15:47:47 4877B077F4CC7EFD4FC7D972D253FA7C 553067 ----a-w- C:\Users\Merino\AppData\Local\Temp\{E67A3ED5-E023-479A-A91F-4955111C104B}\_isres_0x0409.dll 2015-12-22 15:47:47 0F316043BFD136A509347148D203D541 151368 ----a-w- C:\Users\Merino\AppData\Local\Temp\{E67A3ED5-E023-479A-A91F-4955111C104B}\ISBEW64.exe 2015-12-22 15:47:42 6F73970EB4BEA234844E2806AF8EB75B 2128891 ----a-w- C:\Users\Merino\AppData\Local\Temp\{132DD516-D881-4C59-B036-99FDA055727B}\ISSetup.dll 2015-12-22 15:47:33 40B2C2D393DFD1C83D9BF96C4012008C 77331456 ----a-w- C:\Users\Merino\AppData\Local\Temp\{132DD516-D881-4C59-B036-99FDA055727B}\Samsung Kies.msi ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2015-12-29 17:25:47 B9C67D7635EA8F1AC5714F8D1B5364E3 9479872 ----a-w- C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2015-12-28 17:00:09 F4F36D2AA4C3A686F749BF1C46F84C37 32680 ----a-w- C:\Windows\SysWOW64\authuitu.dll 2015-12-27 13:37:50 1EBAD61A39FFA54D0758BFBF7DBD3B12 796864 ----a-w- C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-12-27 13:37:50 06EBAB5CFA01199CB807260951562839 142528 ----a-w- C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-12-22 15:51:22 7753FC56F9CAC4B5AFDA3196DB654F21 144664 ----a-w- C:\Windows\SysWOW64\secman.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2015-12-28 17:00:17 042BCF18CACC921E7B46FEE1A8105C04 46504 ----a-w- C:\Windows\Sysnative\TURegOpt.exe 2015-12-28 17:00:10 29F3CBB16E7A4DAB3B1106227815BDB1 37288 ----a-w- C:\Windows\Sysnative\authuitu.dll ====== C:\Windows\Sysnative\drivers ===== 2015-12-09 00:08:12 5BD6B1EC997FF3DD779D62E05D2079A8 146944 ----a-w- C:\Windows\Sysnative\drivers\rmcast.sys ====== C:\Windows\Tasks ====== 2015-12-29 01:10:41 6A72F09797DC65C098E2F41AA73E801F 2760 ----a-w- C:\Windows\Sysnative\Tasks\AVGPCTuneUp_Task_BkGndMaintenance 2015-12-27 13:37:51 BA9DBF9F02AA9DD1B25E7248377D5089 940 ----a-w- C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-12-27 13:37:51 340537BFDB60516415FF5A8762B110CD 3878 ----a-w- C:\Windows\Sysnative\Tasks\Adobe Flash Player Updater ====== C:\Windows\Temp ====== ======= C:\Program Files ===== ======= C:\PROGRA~2 ===== 2015-12-26 01:30:38 -------- d-----w- C:\PROGRA~2\Free WMA to MP3 Converter 2015-12-26 01:28:22 -------- d-----w- C:\PROGRA~2\Audacity 2015-12-22 15:49:31 -------- d-----w- C:\PROGRA~2\Samsung 2015-12-17 11:42:52 -------- d-----w- C:\PROGRA~2\COMMON~1\DESIGNER 2015-12-04 20:41:20 -------- d-----w- C:\PROGRA~2\x264vfw ======= C: ===== ====== C:\Users\Merino\AppData\Roaming ====== 2015-12-26 01:28:43 -------- d-----w- C:\Users\Merino\AppData\Roaming\Audacity 2015-12-22 15:56:52 -------- d-----w- C:\Users\Merino\AppData\Roaming\Samsung 2015-12-22 15:47:42 -------- d-----w- C:\Users\Merino\AppData\Local\Downloaded Installations 2015-12-17 22:05:47 -------- d-----w- C:\Users\Merino\AppData\Roaming\vlc 2015-12-12 17:17:00 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Dropbox 2015-12-12 17:16:23 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\Dropbox 2015-12-09 23:01:36 -------- d-----w- C:\Users\Default\AppData\Roaming\TuneUp Software 2015-12-09 23:01:36 -------- d-----w- C:\Users\Default User\AppData\Roaming\TuneUp Software 2015-12-07 06:32:39 01992F1385DF5A7DBAD3EF009E7192B0 1870432 ----a-w- C:\Windows\serviceprofiles\Localservice\AppData\Local\FontCache3.0.0.0.dat 2015-12-02 14:55:44 -------- d-----w- C:\Users\Merino\AppData\Local\Programs ====== C:\Users\Merino ====== 2015-12-29 12:53:12 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Merino\Downloads\RSITx64.exe 2015-12-28 16:59:57 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015-12-26 01:30:39 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jodix 2015-12-26 01:30:05 28B89D8AEA77B47A86EBAB90120612B1 948090 ----a-w- C:\Users\Merino\Downloads\free-wma-mp3-converter.exe 2015-12-26 01:28:05 DCCEA87D7FA553604861ADBCB86F4513 25186399 ----a-w- C:\Users\Merino\Downloads\audacity-win-2.1.1.exe 2015-12-22 19:24:15 E43C6D90C73276B88B4C01B371DCE12A 43832704 ----a-w- C:\Users\Merino\Downloads\Kies3Setup.exe 2015-12-22 15:57:56 -------- d-----w- C:\Users\Public\Documents\NativeFus_Log 2015-12-22 15:51:25 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2015-12-22 15:49:31 -------- d-----w- C:\ProgramData\Samsung 2015-12-12 17:17:45 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-12-12 17:16:54 -------- d-----r- C:\Windows\sysWoW64\config\systemprofile\Documents 2015-12-12 17:16:54 -------- d-----r- C:\Windows\sysWoW64\config\systemprofile\Desktop 2015-12-04 20:41:20 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\x264vfw ====== C: exe-files == 2015-12-29 17:25:47 B9C67D7635EA8F1AC5714F8D1B5364E3 9479872 ----a-w- C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2015-12-29 12:53:12 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\Merino\Downloads\RSITx64.exe 2015-12-28 17:00:17 042BCF18CACC921E7B46FEE1A8105C04 46504 ----a-w- C:\Windows\System32\TURegOpt.exe 2015-12-28 16:58:05 F3EF4F73D33DE2DB7DE63D1F385D8830 3141544 ----a-w- C:\Program Files (x86)\AVG\Setup\avgsetupx.exe 2015-12-28 16:58:05 B1B196EAD3B14E6E1C508DEF1A65CED3 797096 ----a-w- C:\Program Files (x86)\AVG\Setup\avgntdumpx.exe 2015-12-27 13:37:50 1EBAD61A39FFA54D0758BFBF7DBD3B12 796864 ----a-w- C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-12-26 01:30:38 992E3F82E5011D521CD32A4923C72594 674779 ----a-w- C:\Program Files (x86)\Free WMA to MP3 Converter\unins000.exe 2015-12-26 01:30:38 523D2E5F9A0459455501769A7FDD513E 1740800 ----a-w- C:\Program Files (x86)\Free WMA to MP3 Converter\wma_mp3_converter.exe 2015-12-26 01:30:05 28B89D8AEA77B47A86EBAB90120612B1 948090 ----a-w- C:\Users\Merino\Downloads\free-wma-mp3-converter.exe 2015-12-26 01:28:22 CFB0BF2F82935BB89B3E939A6D48F8D3 1487127 ----a-w- C:\Program Files (x86)\Audacity\unins000.exe 2015-12-26 01:28:22 C237DF9EB491D6368A90B22FC5085EF1 8441344 ----a-w- C:\Program Files (x86)\Audacity\audacity.exe 2015-12-26 01:28:05 DCCEA87D7FA553604861ADBCB86F4513 25186399 ----a-w- C:\Users\Merino\Downloads\audacity-win-2.1.1.exe === C: other files == 2015-12-26 21:17:27 FEC0232F2823F21B68DCE268BC6C70A2 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-567766478-1147120031-4173233673-1000\$I353FWC.zip 2015-12-26 21:16:00 CD7D5A7B690CADD09DC67E6B76AF666D 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-567766478-1147120031-4173233673-1000\$IWFB3DW.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-567766478-1147120031-4173233673-1000\Software\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite Automount"="C:\Program Files\DAEMON Tools Lite\DTAgent.exe -autorun" "GUDelayStartup"="C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe -delayrun" "Spotify Web Helper"="C:\Users\Merino\AppData\Roaming\Spotify\SpotifyWebHelper.exe" [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:http://go.microsoft.com/fwlink/?LinkID=122915 /build:7601" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="C:\Windows\System32\SPReview\SPReview.exe /sp:1 /errorfwlink:http://go.microsoft.com/fwlink/?LinkID=122915 /build:7601" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AdobeCS6ServiceManager"="C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe -launchedbylogin" "AvgUi"="C:\Program Files (x86)\AVG\Framework\Common\avguix.exe /fmw.trayonly" "AVG_UI"="C:\Program Files (x86)\AVG\Av\avgui.exe /TRAYONLY" "Dropbox"="C:\Program Files (x86)\Dropbox\Client\Dropbox.exe /systemstartup" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite Automount"="C:\Program Files\DAEMON Tools Lite\DTAgent.exe -autorun" "GUDelayStartup"="C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe -delayrun" "Spotify Web Helper"="C:\Users\Merino\AppData\Roaming\Spotify\SpotifyWebHelper.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HP Quick Launch"="C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" "HPWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe /hidden" "AdobeAAMUpdater-1.0"="C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [29-12-2015 18:26] C:\Windows\tasks\DropboxUpdateTaskMachineCore.job --a------ [Undetermined Task] C:\Windows\tasks\DropboxUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [16-11-2015 15:57] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [28-10-2015 12:08] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ [Undetermined Task] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\AdobeAAMUpdater-1.0-Merino-PC-Merino" [C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe] "C:\Windows\SysNative\tasks\AVGPCTuneUp_Task_BkGndMaintenance" [C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe] "C:\Windows\SysNative\tasks\CLMLSvc" [c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Music\Kernel\CLML\CLMLSvc.exe] "C:\Windows\SysNative\tasks\DropboxUpdateTaskMachineCore" [C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe] "C:\Windows\SysNative\tasks\DropboxUpdateTaskMachineUA" [C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe] "C:\Windows\SysNative\tasks\DVDAgent" [c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe] "C:\Windows\SysNative\tasks\GlaryInitialize 5" [C:\Program Files (x86)\Glary Utilities 5\Initialize.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Assistant\PC Tuneup" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Chromium Look ====================== Google Slides - Merino\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek Google Docs - Merino\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Merino\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Merino\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Merino\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Sheets - Merino\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap Google Docs Offline - Merino\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi AdBlock - Merino\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom Chrome Web Store Payments - Merino\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Merino\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02 ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [AvgUi] "C:\Program Files (x86)\AVG\Framework\Common\avguix.exe" /fmw.trayonly O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\Av\avgui.exe" /TRAYONLY O4 - HKLM\..\Run: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun O4 - HKCU\..\Run: [GUDelayStartup] "C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe" -delayrun O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Merino\AppData\Roaming\Spotify\SpotifyWebHelper.exe" O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user') O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office15\EXCEL.EXE/3000 O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~3\Office15\ONBttnIE.dll/105 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\AESTSr64.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: AvgAMPS - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Av\avgamps.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Av\avgidsagent.exe O23 - Service: AVG Service (avgsvc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Av\avgwdsvcx.exe O23 - Service: Dropbox-update-service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe O23 - Service: Dropbox-update-service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe O23 - Service: hpqwmiex - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing) O23 - Service: HPWMISVC - Unknown owner - C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_1c0e2d1db9f5b08e\STacSV64.exe O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Merino\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BI4BQLX9 will be deleted at reboot C:\Users\Merino\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T474FUEY will be deleted at reboot C:\Users\Merino\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TELDK58H will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Merino\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=1898 folders=63 181718633 bytes) ==== Empty Temp Folders ====================== C:\Users\Merino\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Merino\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Program Files (x86)\AVG\AVG PC TuneUp\html.dat" not found "C:\Program Files (x86)\AVG\AVG PC TuneUp" not found "C:\Users\Merino\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BI4BQLX9" not found "C:\Users\Merino\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T474FUEY" not found "C:\Users\Merino\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TELDK58H" not found ==== EOF on wo 30-12-2015 at 16:14:18,78 ======================