Zoek.exe v5.0.0.0 Updated 07-March-2014 Tool run by Emma on zo 09/03/2014 at 20:22:42,11. Microsoft Windows 8 6.2.9200 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Emma\Downloads\zoek (1).exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 9/03/2014 20:24:29 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\Program Files\Symantec deleted successfully C:\PROGRA~3\Oracle deleted successfully C:\Users\Emma\AppData\Local\VirtualStore deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3412688650-2016799533-2931778049-1001\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully HKEY_USERS\S-1-5-21-3412688650-2016799533-2931778049-1001\Software\Microsoft\Internet Explorer\SearchScopes\{5B3D7551-B53F-464F-BBB7-5AD889106C90} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\Users\Emma\AppData\Local\playnowradio deleted C:\Users\Emma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker deleted C:\Users\Emma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com deleted C:\Users\Emma\AppData\LocalLow\Minibar deleted C:\windows\Tasks\Re-markit Update.job deleted C:\windows\Tasks\Re-markit_wd.job deleted C:\Users\Emma\Documents\Optimizer Pro deleted "C:\windows\Installer\171fb.msi" deleted "C:\PROGRA~2\Re-markit\Re-markit154.exe" deleted "C:\Users\Emma\AppData\Local\FilesFrog Update Checker\update_checker.exe" deleted "C:\Users\Emma\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe" deleted "C:\Users\Emma\AppData\Local\FilesFrog Update Checker\update_checker.exe" deleted "C:\Users\Emma\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe" deleted "C:\Users\Emma\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe" deleted "C:\PROGRA~2\Re-markit" not deleted "C:\Users\Emma\AppData\Local\FilesFrog Update Checker" deleted "C:\Users\Emma\AppData\Local\WebPlayer\AppsHat" deleted "C:\Users\Emma\AppData\Local\WebPlayer" deleted "C:\Users\Emma\AppData\Local\FilesFrog Update Checker" deleted "C:\Users\Emma\AppData\Local\WebPlayer\AppsHat" deleted "C:\Users\Emma\AppData\Local\WebPlayer\FLV Player" deleted ==== Files Recently Created / Modified ====================== ====== C:\windows ==== ====== C:\Users\Emma\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\windows\SysWOW64 ===== ====== C:\windows\SysWOW64\drivers ===== ====== C:\windows\Sysnative ===== ====== C:\windows\Sysnative\drivers ===== 2014-02-11 22:59:12 DD4249F03598043DED6FA540EB14898A 2232664 ----a-w- C:\windows\Sysnative\drivers\tcpip.sys 2014-02-11 21:56:51 961A45CC15514178E511BBF1384CE0B8 83968 ----a-w- C:\windows\Sysnative\drivers\hidclass.sys ====== C:\windows\Tasks ====== ====== C:\windows\Temp ====== ======= C:\Program Files ===== 2014-03-09 16:31:47 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2014-02-23 20:31:41 -------- d-----w- C:\PROGRA~2\RAR Password Unlocker 2014-02-23 19:58:38 -------- d-----w- C:\PROGRA~2\WinRAR 2014-02-23 19:53:58 -------- d-----w- C:\PROGRA~2\Re-markit ======= C: ===== ====== C:\Users\Emma\AppData\Roaming ====== 2014-02-25 18:57:28 0C4B1ACB72943D8D024DABD9CDC37F85 7605 ----a-w- C:\Users\Emma\AppData\Local\Resmon.ResmonCfg 2014-02-23 19:59:17 -------- d-----w- C:\Users\Emma\AppData\Roaming\WinRAR 2014-02-23 19:58:58 -------- d-----w- C:\Users\Emma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR ====== C:\Users\Emma ====== 2014-03-09 16:30:44 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\Emma\Downloads\RSITx64.exe 2014-02-23 22:55:19 FF014972889593D268FC5D8071CC2E9E 446952 ----a-w- C:\Users\Emma\Downloads\Het_Vonnis_2013_DVDRip_XviD_Belgium (1).exe 2014-02-23 19:58:59 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-02-23 19:58:05 10862FB395954B2638F24898890BAC63 1769680 ----a-w- C:\Users\Emma\Downloads\wrar501.exe ====== C: exe-files == 2014-03-09 17:50:53 DA14529661D7C7ECB3A202AD4D1EC25E 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$I6NEBST.exe 2014-03-09 17:50:53 1EF10F9DD1B162BDF4BD31A548BCE4A1 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$ISZ7K59.exe 2014-03-09 17:50:52 29365E4C803EA19AFDF00FF5A366DE1C 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IZFA8F6.exe 2014-03-09 17:50:51 477E26EC1B0BD06DCB5184724051D134 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$I101SGH.exe 2014-03-09 16:31:48 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Emma.exe 2014-03-09 16:30:44 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\Emma\Downloads\RSITx64.exe 2014-03-09 15:59:52 6CFACEA88080B43859D6E4C73762A905 152624 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$R101SGH.exe 2014-03-08 14:57:35 99EDAB82414D23D14947415E5C502FE1 786136 ----a-w- C:\Program Files (x86)\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\33.0.1750.146\33.0.1750.146_33.0.1750.117_chrome_updater.exe === C: other files == 2014-03-09 17:51:12 B940CA8F4E491F34461D2669CDFF9C93 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IJCZZ5U.zip 2014-03-09 17:51:12 B4A8A2E4614B2E78378187C7DD9E4EC0 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IBRPO15.zip 2014-03-09 17:51:12 AA75A6D061C0B8176D9FB24765B00480 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$I0X3ULX.zip 2014-03-09 17:51:12 AA23700F31D62DF1966A6FC0715D2506 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IE43L5Q.zip 2014-03-09 17:51:12 255561EE8B070517AE2A60B086DE14E0 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$INWJQBR.zip 2014-03-09 17:51:12 24740C0E53BB4FDEAE069369A0E2DF58 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IG445ZP.zip 2014-03-09 17:51:12 0F11D287E902443EA4293E47B09835D9 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IRGKFS1.zip 2014-03-09 17:51:05 F806C0C681363057C81809DB16FF4F7B 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IP3LRK6.zip 2014-03-09 17:51:05 EECFA9BA8F84CAC3BD8421BDC5BA1B59 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IWCZL5L.zip 2014-03-09 17:51:05 DDB07340F56A42498009FC3D47F06E2E 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IBJCOI8.zip 2014-03-09 17:51:05 DC442EB378FE187A258EE2DFA5670EA9 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IMSTN7P.zip 2014-03-09 17:51:05 94218F94E84A823E15D03F3B618DD88C 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$I1XYSBI.zip 2014-03-09 17:51:05 8E88B5FBDCF5F60C268122B7BBA28A3F 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$INCUX1R.zip 2014-03-09 17:51:05 70F7E991334ECDEA92D6C41E179A7A38 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IROG2BI.zip 2014-03-09 17:51:05 67226F7CC768138960003F435CA0CFCC 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IA8X9Z5.zip 2014-03-09 17:51:05 65A2230AB04FA0F7896555214BA267D6 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IZVTRHP.zip 2014-03-09 17:51:05 5DA9B93E58246D0D83E6485A7CAE0090 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IKN83YX.zip 2014-03-09 17:51:05 4655124601EE788F8B53EEEBECC9CA9E 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$I0CQN5U.zip 2014-03-09 17:51:05 32515AC7ADDCB46AA84BF5150937BADF 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IMNBVDE.zip 2014-03-09 17:51:05 24ECFC6BE8C589900C366D29280E41B3 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IM5HR19.zip 2014-03-09 17:51:05 153C97842E728A132FBD55C1FCE3FD82 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$I89W2MA.zip 2014-03-09 17:51:05 08881888FDD4E9B1D267148704A51E56 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$ICHH4WP.zip 2014-03-09 17:51:05 045F870EE5D4CDFB0C4688CE172DA7A7 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$I7U1A1N.zip 2014-03-09 15:44:21 D8B5AC1DC7079587330E69A30803FBF8 544 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$IIN5OIM.zip 2014-03-09 15:41:10 82BA74B288205CE2CE283F65C865E87D 178623 ----a-r- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$RIN5OIM.zip 2014-03-09 15:10:41 C06886D74EFCC92152DE6EFB47B2EFAD 1281 ----a-w- C:\Users\Emma\Downloads\the.hangover.part.ii.(2011).dut.1cd.(4413638).zip 2014-03-09 15:02:33 BBFDA85C73817FFBE29D8820298E2D2E 1275 ----a-w- C:\Users\Emma\Downloads\the.hangover.(2009).dut.1cd.(3601751).zip 2014-03-09 14:38:48 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\Emma\Downloads\_Greys_Anatomy_1CD_2005_English_srt_subtitles3796808.zip 2014-03-09 14:35:36 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\Emma\Downloads\0844df808b2d40af5161abdf8cabe888745e62fa.zip 2014-03-09 14:32:53 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\Emma\Downloads\_Greys-Anatomy-S05E24-Now-or-Never-2-DVDRip-XviD-REWARD.zip 2014-03-09 14:30:59 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$RBRPO15.zip 2014-03-09 14:27:53 AF87EEA862332B320E33B978F3FCE585 1289 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$RROG2BI.zip 2014-03-09 14:26:31 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\Emma\Downloads\28423.zip 2014-03-09 14:25:05 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\Emma\Downloads\GreysAnatomy_5x24_720pHDTV.DIMENSION.en.zip 2014-03-09 14:21:09 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\Emma\Downloads\28424.zip 2014-03-09 14:19:15 A012C96A809E5D425EB6745E9D140446 1306 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$RMSTN7P.zip 2014-03-09 14:17:49 115EBF0D88A17F5776862F632F219B0B 1308 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$RE43L5Q.zip 2014-03-09 14:12:58 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\Emma\Downloads\26017.zip 2014-03-09 14:11:06 E66E798CC76793F77DF7C2ED17D5DF47 1305 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$RA8X9Z5.zip 2014-03-09 14:09:07 6142BF4D2C71D187E721B360123BF3C4 1309 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$R0CQN5U.zip 2014-03-09 14:07:40 C43C4720551BD4A8D302734847F0911F 1336 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$RM5HR19.zip 2014-03-09 14:06:01 2A3155B035609FBDFFFBF44000F7112E 1305 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$RBJCOI8.zip 2014-03-09 14:03:33 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\Emma\Downloads\30937.zip 2014-03-09 14:02:12 46F9164CC83E9DF07E356D3D947B7C14 1310 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$RWCZL5L.zip 2014-03-09 13:59:34 384A34A4B7F9B760E59CE9750483327F 1310 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$RMNBVDE.zip 2014-03-09 13:55:06 2C20D543863E29E2D53DDB7D5AF07B3E 501948 ----a-w- C:\Users\Emma\Downloads\Ondertitel.com-54-Greys.Anatomy.S05.HDTV.XviD.zip 2014-03-09 13:53:41 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\Emma\Downloads\36d1feaa528ffaa68fed315002105e3e2714b8c3.zip 2014-03-09 13:50:24 76CDB2BAD9582D23C1F6F4D868218D6C 22 ----a-w- C:\Users\Emma\Downloads\44b3d5841ed5b01f75e2490c089d0a70edb8042c.zip 2014-03-09 13:47:22 3B8A2CA5A14AB08F13AA002F105CD390 1331 ----a-w- C:\$RECYCLE.BIN\S-1-5-21-3412688650-2016799533-2931778049-1001\$RCHH4WP.zip 2014-03-08 20:01:29 268D7CA73B95CF8DCCCFEEA29CCCD0A6 37977 ----a-w- C:\Users\Emma\Downloads\915d2e786086072b92676a9938a4367a051a70d6.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-3412688650-2016799533-2931778049-1001\Software\Microsoft\Windows\CurrentVersion\Run] "SDP"="C:\Users\Emma\AppData\Local\FilesFrog Update Checker\update_checker.exe /auto " "Apps Hat"="C:\Users\Emma\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe" "FLV Player"="C:\Users\Emma\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TPUReg"="C:\Program Files (x86)\TOSHIBA\Password Utility\TosPU.exe /Retimes" "TPUReg(x86)"="C:\Program Files\TOSHIBA\Password Utility\TosPU.exe /Retimes" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "GrooveMonitor"="C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "ConnectionCenter"="C:\Program Files (x86)\Citrix\ICA Client\concentr.exe /startup" "Redirector"="C:\Program Files (x86)\Citrix\ICA Client\redirector.exe /startup" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "SDP"="C:\Users\Emma\AppData\Local\FilesFrog Update Checker\update_checker.exe /auto " "Apps Hat"="C:\Users\Emma\AppData\Local\WebPlayer\AppsHat\WebPlayer.exe" "FLV Player"="C:\Users\Emma\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "TODDMain"="C:\Program Files (x86)\TOSHIBA\System Setting\TODDMain.exe" "TecoResident"="C:\Program Files\TOSHIBA\Teco\TecoResident.exe" "SRS Premium Sound HD"="C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe /f=C:\Program Files\SRS Labs\SRS Control Panel\SRS_Premium_Sound_HD.zip /h" "IgfxTray"="C:\windows\system32\igfxtray.exe" "HotKeysCmds"="C:\windows\system32\hkcmd.exe" "Persistence"="C:\windows\system32\igfxpers.exe" "TCrdMain"="%ProgramFiles%\TOSHIBA\Hotkey\TCrdMain_Win8.exe " "TosWaitSrv"="%ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe " ==== Startup Folders ====================== 2013-08-13 23:18:55 1935 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ==== Task Scheduler Jobs ====================== C:\windows\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [09/08/2013 15:34] C:\windows\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [09/08/2013 15:34] ==== Other Scheduled Tasks ====================== "C:\windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\windows\SysNative\tasks\Synaptics TouchPad Enhancements" [\Program Files\Synaptics\SynTP\SynTPEnh.exe] "C:\windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\windows\SysNative\tasks\Symantec\Norton Error Analyzer 5.2.2.3" [C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\SymErr.exe] "C:\windows\SysNative\tasks\Symantec\Norton Error Processor 5.2.2.3" [C:\Program Files (x86)\Norton 360\Engine\5.2.2.3\SymErr.exe] "C:\windows\SysNative\tasks\Toshiba\CommonNotifier" [C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe] "C:\windows\SysNative\tasks\Toshiba\Service Station" ["C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe"] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}"="C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn_2011_7_13_2" [17/02/2014 21:02] ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions bopakagnckmlgajfccecajhnimjiiedh - No path found[] Angry Birds - Emma\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj Google Drive - Emma\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Emma\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - Emma\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Fashion Designer New York - Emma\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfmfbknngdgopopemfjanfbbhmenghfh Timer Countdown Alarm Clock and Stopwatch - Emma\AppData\Local\Google\Chrome\User Data\Default\Extensions\edebbhkhcaafmolanelponjjanocpacd Folds Origami Game - Emma\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnialnikognojeehlgdhiebeggmdaged Plypp Piano - Emma\AppData\Local\Google\Chrome\User Data\Default\Extensions\hofckkgpnnjabffkjemconojemcibifh Autodesk Homestyler - Emma\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb Cargo Bridge - Emma\AppData\Local\Google\Chrome\User Data\Default\Extensions\keembkgclppcbilkekfgpobhldjjhpmn Little Alchemy - Emma\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd Minibar - Emma\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpcknfcdcgpffjddjeceioobdelceffo Google Wallet - Emma\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Emma\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chrome Fix ====================== C:\Users\Emma\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpcknfcdcgpffjddjeceioobdelceffo deleted successfully C:\Users\Emma\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mpcknfcdcgpffjddjeceioobdelceffo_0.localstorage deleted successfully C:\Users\Emma\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mpcknfcdcgpffjddjeceioobdelceffo_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://search.conduit.com/?ctid=CT3314136&octid=EB_ORIGINAL_CTID&SearchSource=61&CUI=&UM=&UP=SP1CBB1113-FC56-45E1-A029-FEFA6E9C8901&SSPV=" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {41EF3FAC-962C-4D08-BD9B-D54333EA4556} FindWide Url="http://search.findwide.com/serp?guid={F5C9EFE2-B866-450E-A13A-E103E5EA4228}&action=default_search&serpv=22&k={searchTerms}" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" {A5C08A1B-A904-4561-AE6E-AAA01CE7AF01} Unknown Url="Not_Found" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3412688650-2016799533-2931778049-1001\Software\Microsoft\Internet Explorer\SearchScopes\{A5C08A1B-A904-4561-AE6E-AAA01CE7AF01} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Reset IE Proxy ====================== Value(s) before fix: "ProxyServer"="http=127.0.0.1:13828" "ProxyOverride"="*.local" "ProxyEnable"=dword:00000001 Value(s) after fix: "ProxyEnable"=dword:00000000 ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\E40670FF068C9E042A033EF74AF101A3 deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FF07604E-C860-40E9-A230-E37FA41F103A} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\E40670FF068C9E042A033EF74AF101A3 deleted successfully ==== Empty IE Cache ====================== C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Emma\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Emma\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Emma\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=99 folders=24 9494419 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Emma\AppData\Local\Temp will be emptied at reboot C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\windows\Temp successfully emptied C:\Users\Emma\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\PROGRA~2\Re-markit" not found ==== EOF on zo 09/03/2014 at 20:48:57,94 ======================