Zoek.exe v5.0.0.0 Updated 14-April-2014 Tool run by Tom en Mel on wo 07-05-2014 at 12:30:46,42. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Tom en Mel\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 7-5-2014 12:31:44 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2705282484-783593068-392022480-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully HKEY_USERS\S-1-5-21-2705282484-783593068-392022480-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] ==== Deleting Files \ Folders ====================== C:\Users\Tom en Mel\AppData\Roaming\sweet-page deleted C:\PROGRA~3\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} deleted C:\PROGRA~3\{18165758-115C-4DC0-9EC2-FF89F725767F} deleted C:\Users\Tom en Mel\AppData\Roaming\eCyber deleted C:\Users\Tom en Mel\AppData\Roaming\iSafe deleted C:\PROGRA~3\WPM deleted C:\PROGRA~3\AVG January 2013 Campaign deleted C:\PROGRA~3\Package Cache deleted C:\Users\Tom en Mel\AppData\Local\CRE deleted C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted C:\Windows\tasks\ROC_REG_JAN_DELETE.job deleted C:\windows\SysNative\tasks\ROC_REG_JAN_DELETE deleted "C:\Users\Tom en Mel\AppData\Roaming\FreePDF" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\TOMENM~1\AppData\Local\Temp ==== ====== Java Cache ===== 2014-04-28 18:44:16 D41D8CD98F00B204E9800998ECF8427E 0 ----a-w- C:\Users\Tom en Mel\AppData\LocalLow\Sun\Java\Deployment\SystemCache\6.0\32\6c34baa0-13198a41 ====== C:\Windows\SysWOW64 ===== 2014-05-03 23:22:45 5869FBC754578A59C8C8635B99DB79DE 17384448 ----a-w- C:\Windows\SysWOW64\mshtml.dll 2014-05-03 23:22:45 2518D1922371892ADEF1F07147DBD72A 2724864 ----a-w- C:\Windows\SysWOW64\mshtml.tlb ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-05-05 19:59:53 1813D880A21093A2C4604D5800F3BA08 576 ----a-w- C:\Windows\Sysnative\F39D4DE6-98B8-4E05-91BD-549E8A8248BD 2014-05-03 23:22:47 A98DA2EC1E56CF52C682D072F77D9874 23547904 ----a-w- C:\Windows\Sysnative\mshtml.dll 2014-05-03 23:22:45 DE5DE05946D6FC2DC494C55BC7BC4C6E 2724864 ----a-w- C:\Windows\Sysnative\mshtml.tlb 2014-05-03 23:22:10 84ED099009EF0DF82A37D4FEAE012655 465408 ----a-w- C:\Windows\Sysnative\aepdu.dll 2014-05-03 23:22:10 5513F4766C9987D6B0D49D51BB2E5EE4 424448 ----a-w- C:\Windows\Sysnative\aeinv.dll ====== C:\Windows\Sysnative\drivers ===== 2014-05-05 20:08:24 CD81F6DF96AC72F4C76ED554041BC9D7 43520 ----a-w- C:\Windows\Sysnative\drivers\iSafeKrnlBoot.sys 2014-04-18 13:01:56 E92276DB995B7E75DA9B9DD271058A8E 237336 ----a-w- C:\Windows\Sysnative\drivers\avgidsdrivera.sys 2014-04-13 15:55:25 B3222734D80013D2C73841B0C549FA63 27584 ----a-w- C:\Windows\Sysnative\drivers\Diskdump.sys 2014-04-13 15:55:25 A3F0BC5897F9D3786A3CB695B163633A 190912 ----a-w- C:\Windows\Sysnative\drivers\storport.sys 2014-04-13 15:55:25 96BB922A0981BC7432C8CF52B5410FE6 274880 ----a-w- C:\Windows\Sysnative\drivers\msiscsi.sys 2014-04-13 15:55:21 1A29A59A4C5BA6F8C85062A613B7E2B2 1684928 ----a-w- C:\Windows\Sysnative\drivers\ntfs.sys ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-05-07 07:37:06 -------- d-----w- C:\Program Files\trend micro 2014-05-03 21:19:35 -------- d-----w- C:\Program Files\HitmanPro 2014-04-16 17:06:13 -------- d-----w- C:\Program Files\Google ======= C:\PROGRA~2 ===== 2014-04-16 17:05:48 -------- d-----w- C:\PROGRA~2\Google ======= C: ===== ====== C:\Users\Tom en Mel\AppData\Roaming ====== 2014-05-05 20:29:22 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\Fighters 2014-05-05 19:24:42 -------- d-----w- C:\Windows\SysNative\config\systemprofile\AppData\Roaming\BullGuard 2014-05-05 19:08:59 -------- d-----w- C:\Users\Tom en Mel\AppData\Roaming\QuickScan 2014-05-05 18:59:44 -------- d-----w- C:\Users\Tom en Mel\AppData\Roaming\Nico Mak Computing 2014-04-16 17:10:26 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google 2014-04-16 16:55:58 -------- d-sh--w- C:\Users\Tom en Mel\AppData\Local\EmieUserList 2014-04-16 16:55:58 -------- d-sh--w- C:\Users\Tom en Mel\AppData\Local\EmieSiteList 2014-04-16 16:55:24 -------- d-sh--w- C:\Users\Tom en Mel\AppData\Locallow\EmieUserList 2014-04-16 16:55:24 -------- d-sh--w- C:\Users\Tom en Mel\AppData\Locallow\EmieSiteList ====== C:\Users\Tom en Mel ====== 2014-05-07 09:05:10 -------- d-----r- C:\Windows\SysNative\config\systemprofile\Searches 2014-05-07 07:36:43 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\Tom en Mel\Desktop\RSITx64.exe 2014-05-07 07:34:28 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\Tom en Mel\Downloads\RSITx64.exe 2014-05-05 20:29:25 -------- d-----w- C:\ProgramData\clp 2014-05-03 21:20:14 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro 2014-05-03 21:19:16 98ADA896D51610D3412EEEAA5F12A53F 10971424 ----a-w- C:\Users\Tom en Mel\Downloads\HitmanPro_x64.exe 2014-05-03 21:18:53 -------- d-----w- C:\ProgramData\HitmanPro ====== C: exe-files == 2014-05-07 07:37:06 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\Tom en Mel.exe 2014-05-07 07:36:43 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\Tom en Mel\Desktop\RSITx64.exe 2014-05-07 07:34:28 662C39FC1E27131551D557862CEC47F0 935175 ----a-w- C:\Users\Tom en Mel\Downloads\RSITx64.exe 2014-05-03 23:22:10 D39F522D9B0033E50C7F54138CFBC0D8 31232 ----a-w- C:\Windows\System32\CompatTel\wicainventory.exe 2014-05-03 23:22:10 21EDB6E45163A5635D6D6307EB42BC77 104960 ----a-w- C:\Windows\System32\CompatTel\QueryAppBlock.exe 2014-05-03 21:20:15 CD3FE805E00666E4CDF6C92BD6F290ED 127752 ----a-w- C:\Program Files\HitmanPro\hmpsched.exe 2014-05-03 21:20:14 98ADA896D51610D3412EEEAA5F12A53F 10971424 ----a-w- C:\Program Files\HitmanPro\HitmanPro.exe 2014-05-03 21:19:16 98ADA896D51610D3412EEEAA5F12A53F 10971424 ----a-w- C:\Users\Tom en Mel\Downloads\HitmanPro_x64.exe === C: other files == 2014-05-05 20:08:24 CD81F6DF96AC72F4C76ED554041BC9D7 43520 ----a-w- C:\Windows\System32\drivers\iSafeKrnlBoot.sys ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-2705282484-783593068-392022480-1001\Software\Microsoft\Windows\CurrentVersion\Run] "Google Update"="C:\Users\Tom en Mel\AppData\Local\Google\Update\GoogleUpdate.exe /c" "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "USB3MON"="C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" "HPOSD"="C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe" "HP CoolSense"="C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey" "AVG_UI"="C:\Program Files (x86)\AVG\AVG2014\avgui.exe /TRAYONLY" "HP Quick Launch"="C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Google Update"="C:\Users\Tom en Mel\AppData\Local\Google\Update\GoogleUpdate.exe /c" "CCleaner Monitoring"="C:\Program Files\CCleaner\CCleaner64.exe /MONITOR" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" "SetDefault"="C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " "SysTrayApp"="C:\Program Files\IDT\WDM\sttray64.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "NCPluginUpdater"="C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe Update" ==== Startup Registry Disabled ====================== [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run-] "Google Update"="\"C:\\Users\\Tom en Mel\\AppData\\Local\\Google\\Update\\GoogleUpdate.exe\" /c" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "Easybits Recovery"="C:\\Program Files (x86)\\EasyBits For Kids\\ezRecover.exe" "Adobe ARM"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\"" ==== Startup Folders ====================== 2012-05-03 00:50:00 836 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [29-04-2014 23:40] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2705282484-783593068-392022480-1001Core.job --a------ C:\Users\Tom en Mel\AppData\Local\Google\Update\GoogleUpdate.exe [07-09-2012 08:46] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2705282484-783593068-392022480-1001UA.job --a------ C:\Users\Tom en Mel\AppData\Local\Google\Update\GoogleUpdate.exe [07-09-2012 08:46] C:\Windows\tasks\HPCeeScheduleForTom en Mel.job --a------ C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [15-07-2011 05:43] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\Adobe-online actualiseringsprogramma" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\Google Updater and Installer" [C:\Users\Tom en Mel\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-2705282484-783593068-392022480-1001Core" [C:\Users\Tom en Mel\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-2705282484-783593068-392022480-1001UA" [C:\Users\Tom en Mel\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\HPCeeScheduleForTom en Mel" [C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe] "C:\Windows\SysNative\tasks\Java Update Scheduler" [C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe] "C:\Windows\SysNative\tasks\MirageAgent" [C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe] "C:\Windows\SysNative\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{FFBD1555-F1A3-4F6C-A9CD-2CF7B1125B41}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\{1AAE1279-DE03-462B-88C7-02C38FBEC445}" ["c:\program files (x86)\internet explorer\iexplore.exe" http://ui.skype.com/ui/0/5.10.0.116.259/nl/abandoninstall?source=lightinstaller&page=tsInstall] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\Update Check" [C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions cjofdnhdkbflacojpfpkchgafjahijbb - C:\Users\Tom en Mel\AppData\Local\CRE\cjofdnhdkbflacojpfpkchgafjahijbb.crx[] lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[11-04-2014 19:46] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions cjofdnhdkbflacojpfpkchgafjahijbb - C:\Users\Tom en Mel\AppData\Local\CRE\cjofdnhdkbflacojpfpkchgafjahijbb.crx[] YouTube - Tom en Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo uTorrentBar_NL - Tom en Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjofdnhdkbflacojpfpkchgafjahijbb Google Search - Tom en Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Skype Click to Call - Tom en Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl Google Wallet - Tom en Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda Gmail - Tom en Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chrome Fix ====================== C:\Users\Tom en Mel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cjofdnhdkbflacojpfpkchgafjahijbb_0.localstorage deleted successfully C:\Users\Tom en Mel\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_cjofdnhdkbflacojpfpkchgafjahijbb_0 deleted successfully C:\Users\Tom en Mel\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cjofdnhdkbflacojpfpkchgafjahijbb deleted successfully C:\Users\Tom en Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjofdnhdkbflacojpfpkchgafjahijbb deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://google.nl/" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.sweet-page.com/web/?type=ds&ts=1396448298&from=sof&uid=ST9500325AS_S2WKSMCN&q={searchTerms}" "Search Page"="http://www.sweet-page.com/web/?type=ds&ts=1396448298&from=sof&uid=ST9500325AS_S2WKSMCN&q={searchTerms}" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.sweet-page.com/web/?type=ds&ts=1396448298&from=sof&uid=ST9500325AS_S2WKSMCN&q={searchTerms}" "Search Page"="http://www.sweet-page.com/web/?type=ds&ts=1396448298&from=sof&uid=ST9500325AS_S2WKSMCN&q={searchTerms}" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://google.nl/" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0191A6B0-1154-4C22-9182-23A95BBE92D9}" {0191A6B0-1154-4C22-9182-23A95BBE92D9} Google Url="https://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Unknown Url="Not_Found" {65EDBA69-1787-45CB-A49A-DFDF72AF491B} Google Url="http://www.google.nl/search?hl=nl&q={searchTerms}" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" {CB149E5F-B052-4A64-A74C-C4BD997CD829} Unknown Url="Not_Found" {D944BB61-2E34-4DBF-A683-47E505C587DC} eBay Url="http://rover.ebay.com/rover/1/1346-111086-4124-10/4?satitle={searchTerms}" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2705282484-783593068-392022480-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully HKEY_USERS\S-1-5-21-2705282484-783593068-392022480-1001\Software\Microsoft\Internet Explorer\SearchScopes\{CB149E5F-B052-4A64-A74C-C4BD997CD829} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\cjofdnhdkbflacojpfpkchgafjahijbb deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\cjofdnhdkbflacojpfpkchgafjahijbb deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4OSRVRSO will be deleted at reboot C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AN824GUA will be deleted at reboot C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1ET3CQPV will be deleted at reboot C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\3HHQGFN4 will be deleted at reboot C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MK652W9T will be deleted at reboot C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MT8DWM0X will be deleted at reboot C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\TDEHD4MK will be deleted at reboot C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN5CH1GZ will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Tom en Mel\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=264 folders=42 41994387 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Tom en Mel\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\TOMENM~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found "C:\Users\Tom en Mel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjofdnhdkbflacojpfpkchgafjahijbb" not found "C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4OSRVRSO" deleted "C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AN824GUA" deleted "C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1ET3CQPV" not found "C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\3HHQGFN4" not found "C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MK652W9T" not found "C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MT8DWM0X" not found "C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\TDEHD4MK" not found "C:\Users\Tom en Mel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZN5CH1GZ" not found "C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted ==== EOF on wo 07-05-2014 at 12:42:58,48 ======================