Zoek.exe v5.0.0.0 Updated 06-August-2014 Tool run by William on za 16/08/2014 at 15:56:07,41. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Safe Mode MINIMAL No Internet Access Detected Launched: C:\Users\William\Desktop\zoek (2).exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== ==== Empty Folders Check ====================== C:\PROGRA~2\CheckPoint deleted successfully C:\PROGRA~2\GUMBC0E.tmp deleted successfully C:\PROGRA~2\MSXML 4.0 deleted successfully C:\PROGRA~2\trend micro deleted successfully C:\PROGRA~2\COMMON~1\Symantec Shared deleted successfully C:\Program Files\CheckPoint deleted successfully C:\Program Files\log deleted successfully C:\PROGRA~3\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 deleted successfully C:\PROGRA~3\4shared Desktop deleted successfully C:\PROGRA~3\Babylon deleted successfully C:\Users\PROSUP\AppData\Roaming\ClickPotatoLite deleted successfully C:\Users\PROSUP\AppData\Roaming\Systweak deleted successfully C:\Users\PROSUP\AppData\Roaming\Windows Live Writer deleted successfully C:\Users\Doris\AppData\Local\{01FF2C35-55BB-4552-97C7-2F4FA216DA97} deleted successfully C:\Users\Doris\AppData\Local\{047E56A4-8039-42A5-8D22-2E47D1DB1345} deleted successfully C:\Users\Doris\AppData\Local\{05E7D5F8-E675-4B50-A566-DA65D1BD122C} deleted successfully C:\Users\Doris\AppData\Local\{09B47C4C-8F91-4464-8172-7056837549E4} deleted successfully C:\Users\Doris\AppData\Local\{0AE9FEF9-E900-4B62-B6D3-47C43A85D95B} deleted successfully C:\Users\Doris\AppData\Local\{0F05D98C-6067-4D2D-9C01-ABDBB09BFBC0} deleted successfully C:\Users\Doris\AppData\Local\{0FBAD838-DA74-4495-BD28-38DC6EFEB63B} deleted successfully C:\Users\Doris\AppData\Local\{1053D047-124C-4A51-8E10-1764D9E09745} deleted successfully C:\Users\Doris\AppData\Local\{133D2D45-E02D-4ADA-8E80-5DDD0BF8D28B} deleted successfully C:\Users\Doris\AppData\Local\{18388067-C398-4FF4-9A1A-35B39B310015} deleted successfully C:\Users\Doris\AppData\Local\{1A2CC2EE-B717-416C-88B6-9F627018AB6E} deleted successfully C:\Users\Doris\AppData\Local\{27BC1C3D-A01B-4576-991A-AE4B2078B70C} deleted successfully C:\Users\Doris\AppData\Local\{2D5E77F4-2B44-4A49-B149-1051665009A9} deleted successfully C:\Users\Doris\AppData\Local\{2DE030F2-1B66-4DBD-B917-25478AAB70CF} deleted successfully C:\Users\Doris\AppData\Local\{3209DA2A-E3C6-4577-AD8A-C5FDC176A5E7} deleted successfully C:\Users\Doris\AppData\Local\{3963AD83-17C3-4C0D-92F6-14C3DEF4CCD6} deleted successfully C:\Users\Doris\AppData\Local\{417E496E-D863-4909-BB24-330BEB90706B} deleted successfully C:\Users\Doris\AppData\Local\{424B24B0-9340-4CCC-A5EA-1DD21F612F7D} deleted successfully C:\Users\Doris\AppData\Local\{4DB3B999-71F3-4B83-A830-11FC0E6E3CA7} deleted successfully C:\Users\Doris\AppData\Local\{5027067C-ACB4-4E1C-B0D1-E2C74C904FDC} deleted successfully C:\Users\Doris\AppData\Local\{50EDB43C-1531-4B68-AE59-A02E47D51138} deleted successfully C:\Users\Doris\AppData\Local\{5A5BD8C3-1C2D-452C-982A-59F05AABEDB3} deleted successfully C:\Users\Doris\AppData\Local\{5E159BF3-EC14-4AB7-8C8E-F645D88D1ECD} deleted successfully C:\Users\Doris\AppData\Local\{612B18F0-B8C3-472F-805C-C3D02060C9F9} deleted successfully C:\Users\Doris\AppData\Local\{64BB64F1-E6DD-4B00-A15C-759362D2D8D5} deleted successfully C:\Users\Doris\AppData\Local\{64C0912C-FAC2-40A6-B53F-C36ECAB0E8D5} deleted successfully C:\Users\Doris\AppData\Local\{6B2D7E64-2591-453B-9C53-F11803AA8883} deleted successfully C:\Users\Doris\AppData\Local\{6E71190F-1C40-4EB0-8FFF-9B58ECFDB2E2} deleted successfully C:\Users\Doris\AppData\Local\{7643F0D4-D83F-47C3-9FC8-92800CA87FC4} deleted successfully C:\Users\Doris\AppData\Local\{79C1613D-CC71-4061-8878-4C961C9F93F7} deleted successfully C:\Users\Doris\AppData\Local\{7A34F29E-B281-4358-AB54-2743E7BBA200} deleted successfully C:\Users\Doris\AppData\Local\{7D4A16F0-6FF7-4DD7-B260-160D7E16957D} deleted successfully C:\Users\Doris\AppData\Local\{8AB9FC87-5E8B-4644-9405-0D49AFD4C56E} deleted successfully C:\Users\Doris\AppData\Local\{8B6BB9B9-EF08-4907-84D9-D664DF32ED0C} deleted successfully C:\Users\Doris\AppData\Local\{8CDCE82A-E7A9-4E58-825D-1822AD5187A6} deleted successfully C:\Users\Doris\AppData\Local\{8DD331F6-A8E5-44D8-87A4-8C804E7FF1A9} deleted successfully C:\Users\Doris\AppData\Local\{92368D70-4B44-44EC-9596-BEB208B1AC89} deleted successfully C:\Users\Doris\AppData\Local\{9766552D-238E-4F98-BBFE-0E6B9D17D28B} deleted successfully C:\Users\Doris\AppData\Local\{AFCD3C9C-0DCC-4B93-9FD9-15CD3DCFF5F0} deleted successfully C:\Users\Doris\AppData\Local\{B10CBCA7-5ACF-40C3-8513-C745CD240058} deleted successfully C:\Users\Doris\AppData\Local\{B172789A-C81D-4B29-8365-AE002EA26B41} deleted successfully C:\Users\Doris\AppData\Local\{B752EB7B-15B2-45F6-88F0-1F9B96EB99D7} deleted successfully C:\Users\Doris\AppData\Local\{B8C05F4F-3EF3-40B4-843E-12EF22CEAD4C} deleted successfully C:\Users\Doris\AppData\Local\{BFC905A0-5FD4-4FD5-A116-BDA388CEE122} deleted successfully C:\Users\Doris\AppData\Local\{C5802D58-2779-4C8B-BCD3-90CA654C4A59} deleted successfully C:\Users\Doris\AppData\Local\{E0743256-09C0-479D-B5D5-C4FE870F7C8F} deleted successfully C:\Users\Doris\AppData\Local\{E1C3F847-B1DC-47F4-954F-3CB0726E221A} deleted successfully C:\Users\Doris\AppData\Local\{EEDFB0BE-C5EF-42A5-83BE-89C0E4A63E37} deleted successfully C:\Users\Doris\AppData\Local\{F632697B-4435-4CAF-A981-97B0A19C78AE} deleted successfully C:\Users\Doris\AppData\Local\{F80246CB-8F91-4F0D-B3FE-853D64BCF9DE} deleted successfully C:\Users\Doris\AppData\Local\{F98E391C-0150-4FF0-9ABD-05C276B537CF} deleted successfully C:\Users\Doris\AppData\Local\{FBCB5477-D8A2-4EFB-A013-15E296ACAED8} deleted successfully C:\Users\PROSUP\AppData\Local\Conduit deleted successfully C:\Users\PROSUP\AppData\Local\DassaultSystemes deleted successfully C:\Users\PROSUP\AppData\Local\{27B88655-FD85-49CA-988D-8FA4C4109805} deleted successfully C:\Users\PROSUP\AppData\Local\{57D9366C-EAFA-4D0C-8C50-D27311841B1D} deleted successfully C:\Users\PROSUP\AppData\Local\{BA161AA1-904E-4F5B-8AC8-97F565A02163} deleted successfully C:\Users\PROSUP\AppData\Local\{F4AA084D-1749-4824-B3FB-343D6E05146C} deleted successfully C:\Users\William\AppData\Local\Axialis deleted successfully C:\Users\William\AppData\Local\Conduit deleted successfully C:\Users\William\AppData\Local\DassaultSystemes deleted successfully C:\Users\CLIA~1\AppData\Local\{14BA4282-D34C-49E2-AF9D-8FC837B6DD92} deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Internet Explorer\SearchScopes\{98FF7F34-931B-4805-83B7-6037DF741A20} deleted successfully HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Internet Explorer\SearchScopes\{F3BD9741-6EC7-47DB-AC4B-1675E80C8D71} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{95B7759C-8C7F-4BF1-B163-73684A933233} deleted successfully ==== Running Processes ====================== C:\Users\William\Desktop\zoek (2).exe C:\windows\SysWOW64\cmd.exe C:\windows\SysWOW64\cmd.exe C:\windows\SysWOW64\cmd.exe ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IswSvc deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\IswSvc deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SrvUpdater deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrvUpdater deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\SrvUpdater deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SrvUpdater deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vToolbarUpdater18.1.0 deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vToolbarUpdater18.1.0 deleted successfully ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00cbb66b-1d3b-46d3-9577-323a336acb50}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8B8B2E80-1444-451D-AC8E-EB9A847F3887}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Sweetpacks COMMUNICATOR"=- "vProt"=- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "AVG-Secure-Search-Update_0913b"=- ==== Deleting Files \ Folders ====================== C:\PROGRA~3\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 not found "C:\Users\William\AppData\Roaming\AVG 0913b Campaign\AVG-Secure-Search-Update-0913b.exe" not found C:\Program Files (x86)\BrowserCompanion deleted C:\Program Files (x86)\Unitech LLC\ividi deleted C:\Program Files (x86)\SweetIM deleted C:\Program Files (x86)\AVG Nation toolbar deleted C:\PROGRA~3\DivX deleted C:\PROGRA~3\StarApp deleted C:\PROGRA~2\SoftwareUpdater deleted C:\PROGRA~2\COMPlus Applications deleted C:\PROGRA~2\ShoppingReport2 deleted C:\PROGRA~2\smartdl deleted C:\PROGRA~2\ChatZum Toolbar deleted C:\PROGRA~2\DAEMON Tools Toolbar deleted C:\PROGRA~2\BabylonToolbar deleted C:\PROGRA~2\Unitech LLC deleted C:\PROGRA~2\iVIDI.org plugin deleted C:\PROGRA~2\1ClickDownload deleted C:\PROGRA~2\sweetpacks bundle uninstaller deleted C:\PROGRA~2\Hotspot Shield deleted C:\PROGRA~2\Conduit deleted C:\PROGRA~2\COMMON~1\AVG Secure Search deleted C:\found.000 deleted C:\found.001 deleted C:\found.002 deleted C:\found.003 deleted C:\Users\PROSUP\AppData\Roaming\BrowserCompanion deleted C:\Users\PROSUP\AppData\Roaming\Babylon deleted C:\Users\PROSUP\AppData\Roaming\BabylonToolbar deleted C:\Users\PROSUP\AppData\Roaming\OpenCandy deleted C:\Users\William\AppData\Roaming\SkypEmoticons deleted C:\Users\William\AppData\Roaming\Unitech LLC deleted C:\Users\William\AppData\Roaming\Babylon deleted C:\Users\William\AppData\Roaming\GetRightToGo deleted C:\Users\William\AppData\Roaming\Systweak deleted C:\Users\William\AppData\Roaming\iPumper deleted C:\Users\CLIA~1\AppData\Roaming\B1Toolbar deleted C:\Users\William\TEMP_PRJ.TMP deleted C:\Users\William\Men21B8.tmp deleted C:\Users\William\PP_ROTATE_SLIDE.TMP deleted C:\PROGRA~3\Browser Manager deleted C:\PROGRA~3\Ask deleted C:\PROGRA~3\AlawarWrapper deleted C:\PROGRA~3\hash.dat deleted C:\PROGRA~3\Hotspot Shield deleted C:\PROGRA~3\AVG Security Toolbar deleted C:\PROGRA~3\Partner deleted C:\PROGRA~3\DSearchLink deleted C:\PROGRA~3\OberonGameConsole deleted C:\PROGRA~3\SweetIM deleted C:\PROGRA~3\AVG Nation toolbar deleted C:\PROGRA~3\AVG Secure Search deleted C:\PROGRA~3\ClickPotatoLiteSA deleted C:\PROGRA~3\InstallMate deleted C:\PROGRA~3\Tarma Installer deleted C:\PROGRA~3\Trymedia deleted C:\Users\Doris\AppData\Local\AVG Secure Search deleted C:\Users\Doris\AppData\Local\AVG Nation toolbar deleted C:\Users\PROSUP\AppData\Local\AVG Secure Search deleted C:\Users\PROSUP\AppData\Local\AVG Nation toolbar deleted C:\Users\PROSUP\AppData\Local\Babylon deleted C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data deleted C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences deleted C:\Users\William\AppData\Local\AVG Secure Search deleted C:\Users\William\AppData\Local\AVG Nation toolbar deleted C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\bprotector web data deleted C:\Users\CLIA~1\AppData\Local\AVG Nation toolbar deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ClickPotato deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SkypEmoticons deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield deleted C:\Users\William\Searches deleted C:\Users\Doris\AppData\LocalLow\AVG Secure Search deleted C:\Users\Doris\AppData\LocalLow\AVG Nation toolbar deleted C:\Users\Doris\AppData\LocalLow\bbrs_002.tb deleted C:\Users\Doris\AppData\LocalLow\Unitech LLC deleted C:\Users\Doris\AppData\LocalLow\PriceGong deleted C:\Users\Doris\AppData\LocalLow\Conduit deleted C:\Users\PROSUP\AppData\LocalLow\ShoppingReport2 deleted C:\Users\PROSUP\AppData\LocalLow\AVG Nation toolbar deleted C:\Users\PROSUP\AppData\LocalLow\bbrs_002.tb deleted C:\Users\PROSUP\AppData\LocalLow\BabylonToolbar deleted C:\Users\PROSUP\AppData\LocalLow\Unitech LLC deleted C:\Users\PROSUP\AppData\LocalLow\Conduit deleted C:\Users\PROSUP\AppData\LocalLow\Toolbar4 deleted C:\Users\William\AppData\LocalLow\ShoppingReport2 deleted C:\Users\William\AppData\LocalLow\AVG Security Toolbar deleted C:\Users\William\AppData\LocalLow\SweetIM deleted C:\Users\William\AppData\LocalLow\AVG Secure Search deleted C:\Users\William\AppData\LocalLow\AVG Nation toolbar deleted C:\Users\William\AppData\LocalLow\bbrs_002.tb deleted C:\Users\William\AppData\LocalLow\Unitech LLC deleted C:\Users\William\AppData\LocalLow\PriceGong deleted C:\Users\William\AppData\LocalLow\Conduit deleted C:\Users\CLIA~1\AppData\LocalLow\AVG Nation toolbar deleted C:\Users\CLIA~1\AppData\LocalLow\bbrs_002.tb deleted C:\Users\CLIA~1\AppData\LocalLow\AskToolbar deleted C:\Users\CLIA~1\AppData\LocalLow\Unitech LLC deleted C:\windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted C:\windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG Nation toolbar deleted C:\windows\SysWow64\searchplugins deleted C:\windows\SysWow64\Extensions deleted C:\Users\Public\Desktop\YouTube Downloader.lnk deleted C:\Users\Public\Desktop\Babylon.lnk deleted C:\windows\Installer\{A0C9DF2B-89B5-4483-8983-18A68200F1B4} deleted C:\Users\William\AppData\Roaming\OH14GMMJQ0.exe deleted C:\PROGRA~3\irecovery.exe deleted "C:\windows\Installer\2b7f87.msi" deleted "C:\windows\Installer\2b7f8d.msi" deleted "C:\windows\Installer\2b7f81.msi" deleted "C:\Users\William\AppData\Roaming\explorers" deleted ==== System Specs ====================== Operating System: Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 64-bits Manufacturer: SAMSUNG ELECTRONICS CO., LTD. - Model: R530/R730/P530 Install Date: 17/12/2010 18:56:19 Last Boot: 16/08/2014 15:51:50 Processor: Intel(R) Core(TM) i3 CPU M 350 @ 2.27GHz Number of Processors: 4 Work Station Bootmode: Fail-safe boot Total RAM: 3956 MB ( - 0) Computername: PROSUP-PC Domain: WORKGROUP User: William (Non-Administrator account) Local Disk: C:\ - NTFS - 202 GB (free 20 GB) Local Disk: D:\ - NTFS - 247 GB (free 21 GB) CD \ DVD Drive: E:\ CD \ DVD Drive: F:\ Bootdevice: \Device\HarddiskVolume2 Windows update: Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: AVG AntiVirus Free Edition 2014 On-access scanning disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Anti-Spyware: AVG AntiVirus Free Edition 2014 disabled (Outdated) Firewall: AVG Internet Security 2014 disabled Default Browser: Google Chrome 24.0.1312.57 Internet Explorer Version: 9.0.8112.16421 Google Chrome version: 24.0.1312.57 Adobe Reader version: 9.1.0.2009022700 Sun Java version: 1.6.0_31 (32-bit) Shockwave Player version: 11.5.9r620 ==== Files Recently Created / Modified ====================== ====== C:\windows ==== ====== C:\Users\William\AppData\Local\Temp ==== 2014-08-04 11:09:07 B135FC75CAA27DE9314E7D980C51ACAF 344992 ----atw- C:\Users\William\AppData\Local\Temp\n6685\s6685.exe ====== Java Cache ===== ====== C:\windows\SysWOW64 ===== ====== C:\windows\SysWOW64\drivers ===== ====== C:\windows\Sysnative ===== ====== C:\windows\Sysnative\drivers ===== 2014-08-13 20:17:34 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\windows\Sysnative\drivers\Msft_User_WUDFUsbccidDriver_01_09_00.Wdf ====== C:\windows\Tasks ====== ====== C:\windows\Temp ====== ======= C:\Program Files ===== ======= C:\PROGRA~2 ===== 2014-07-24 11:58:48 -------- d-----w- C:\PROGRA~2\COMMON~1\Skype ======= C: ===== ====== C:\Users\William\AppData\Roaming ====== 2014-08-11 16:22:01 -------- d-----w- C:\Users\William\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2014-07-24 11:59:11 -------- d-----w- C:\Users\William\AppData\Local\Skype ====== C:\Users\William ====== 2014-08-14 09:06:55 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\William\Downloads\RSIT.exe 2014-08-13 20:55:34 2C209D8021C6A0BD2FBBD9EA7987A2C3 19052720 ----a-w- C:\Users\PROSUP\Downloads\flashplayer_14_ax_debug.exe 2014-08-13 20:32:18 B2E88A6033AFFFB634872015D329A2A2 45870584 ----a-w- C:\Users\PROSUP\Downloads\eID-QuickInstaller-407-7453-signed_tcm227-246722.exe 2014-08-10 20:37:59 3C166BAE84553D4CB27AF8ABDC61712D 675988 ----a-w- C:\Users\William\Downloads\Minecraft.exe 2014-07-24 11:58:48 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype ====== C: exe-files == 2014-08-14 09:07:42 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\William\Desktop\RSIT\RSIT.exe 2014-08-14 09:06:55 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\William\Downloads\RSIT.exe 2014-08-13 20:55:34 2C209D8021C6A0BD2FBBD9EA7987A2C3 19052720 ----a-w- C:\Users\PROSUP\Downloads\flashplayer_14_ax_debug.exe 2014-08-13 20:32:18 B2E88A6033AFFFB634872015D329A2A2 45870584 ----a-w- C:\Users\PROSUP\Downloads\eID-QuickInstaller-407-7453-signed_tcm227-246722.exe 2014-08-13 20:31:41 B2E88A6033AFFFB634872015D329A2A2 45870584 ----a-w- C:\Users\PROSUP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H0T57NBU\eID-QuickInstaller-407-7453-signed_tcm227-246722.exe 2014-08-11 10:13:26 786AB180BAF57CE85B7DC5F4DA37D666 12217271 ----a-w- C:\Users\William\Desktop\Eloth_Final_16_06_2014\starter.exe 2014-08-11 10:13:25 55A18DD00DBC4A1ECEA817F570E14E00 19086020 ----a-w- C:\Users\William\Desktop\Eloth_Final_16_06_2014\patcher\patcher.exe 2014-08-11 10:13:07 855C0C21EB0FB0880347F95CC7664B8B 258048 ----a-w- C:\Users\William\Desktop\Eloth_Final_16_06_2014\config.exe 2014-08-10 20:37:59 3C166BAE84553D4CB27AF8ABDC61712D 675988 ----a-w- C:\Users\William\Downloads\Minecraft.exe === C: other files == 2014-08-11 13:36:17 FD8F7E76B55C5516A70DB19C39201494 994291 ----a-w- C:\Users\William\Downloads\gui-api(adg).zip 2014-08-10 20:18:09 2139B41C2EDB7FB546E59A55F9E9FC61 596564 ----a-w- C:\Users\William\Downloads\CustomMobSpawner 3.2.0.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" "bot.exe"="G:\runescepe\bot.exe" "DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun" "se"="C:\Users\William\AppData\Roaming\SkypEmoticons\SE.exe /minimized " "Steam"="D:\staem\Steam.exe -silent" "RGSC"="D:\Rockstar Games Social Club\RGSCLauncher.exe /silent" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "UpdateLBPShortCut"="C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\CyberLink\LabelPrint UpdateWithCreateOnce Software\CyberLink\LabelPrint\2.5 " "CLMLServer"="C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe " "UpdateP2GoShortCut"="C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\CyberLink\Power2Go UpdateWithCreateOnce SOFTWARE\CyberLink\Power2Go\6.0 " "UpdatePDRShortCut"="C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\CyberLink\PowerDirector UpdateWithCreateOnce Software\CyberLink\PowerDirector\7.0 " "RemoteControl8"="C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe " "PDVD8LanguageShortcut"="C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe " "UpdatePPShortCut"="C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\CyberLink\PowerProducer UpdateWithCreateOnce Software\CyberLink\PowerProducer\5.0" "UpdatePSTShortCut"="C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\CyberLink\DVD Suite UpdateWithCreateOnce Software\CyberLink\PowerStarter" "APLangApp"="C:\Program Files (x86)\AnyPC Client\APLangApp.exe" "UCam_Menu"="C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\CyberLink\YouCam UpdateWithCreateOnce Software\CyberLink\YouCam\2.0 " "SweetIM"="C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe " "Sweetpacks Communicator"="C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe " "AVG_UI"="C:\Program Files (x86)\AVG\AVG2014\avgui.exe /TRAYONLY" "vProt"="C:\Program Files (x86)\AVG Nation toolbar\vprot.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" "bot.exe"="G:\runescepe\bot.exe" "DAEMON Tools Lite"="C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe -autorun" "se"="C:\Users\William\AppData\Roaming\SkypEmoticons\SE.exe /minimized " "Steam"="D:\staem\Steam.exe -silent" "RGSC"="D:\Rockstar Games Social Club\RGSCLauncher.exe /silent" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "NvCplDaemon"="RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup" "Logitech Download Assistant"="C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch" "EvtMgr6"="C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " ==== Startup Registry Disabled ====================== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "Adobe Reader Speed Launcher"="\"C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\"" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\APSDaemon] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="APSDaemon" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iTunesHelper] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="iTunesHelper" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\iTunes\\iTunesHelper.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PC Suite Tray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PC Suite Tray" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Nokia\\Nokia PC Suite 7\\PCSuite.exe\" -onlytray" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="QuickTime Task" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\QuickTime\\QTTask.exe\" -atboottime" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ROC_roc_dec12] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ROC_roc_dec12" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\AVG Secure Search\\ROC_roc_dec12.exe\" /PROMPT /CMPID=roc_dec12" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\swg] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="swg" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\vProt] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="vProt" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\AVG Secure Search\\vprot.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^PROSUP^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2 .lnk] "path"="C:\\Users\\PROSUP\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OpenOffice.org 3.2 .lnk" "backup"="C:\\windows\\pss\\OpenOffice.org 3.2 .lnk.Startup" "backupExtension"=".Startup" "command"="C:\\PROGRA~2\\OPENOF~1.ORG\\program\\QUICKS~1.EXE " "item"="OpenOffice.org 3.2 " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\ServiceLayer] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\SolidWorks Licensing Service] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\vToolbarUpdater] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-] "ISW"="" ==== Startup Folders ====================== 2011-03-16 12:01:20 1235 ----a-w- C:\Users\Doris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2 .lnk 2013-02-02 18:18:03 2193 ----a-w- C:\Users\PROSUP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tcbhn.lnk 2010-12-18 10:31:12 1235 ----a-w- C:\Users\William\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2 .lnk 2013-04-08 17:22:07 1195 ----a-w- C:\Users\CLIA~1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2 .lnk ==== Task Scheduler Jobs ====================== C:\windows\tasks\Adobe Flash Player Updater.job --a------ C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [09/07/2014 19:04] C:\windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [18/12/2010 12:33] C:\windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [18/12/2010 12:33] C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-543984391-606257222-1702330859-1005Core.job --a------ C:\Users\Doris\AppData\Local\Google\Update\GoogleUpdate.exe [01/08/2011 02:25] C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-543984391-606257222-1702330859-1005UA.job --a------ C:\Users\Doris\AppData\Local\Google\Update\GoogleUpdate.exe [01/08/2011 02:25] C:\windows\tasks\Norton Security Scan for PROSUP.job --ah----- C:\Program Files (x86)\Norton Security Scan\Engine\2.7.3.34\Nss.exe [28/06/2010 10:48] ==== Other Scheduled Tasks ====================== "C:\windows\SysNative\tasks\Adobe Flash Player Updater" [C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\windows\SysNative\tasks\advSRS4" ["C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe"] "C:\windows\SysNative\tasks\APSchedulerC" [C:\Program Files (x86)\AnyPC Client\APLanMgrC.exe] "C:\windows\SysNative\tasks\BatteryLifeExtender" [C:\Program Files (x86)\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe] "C:\windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\windows\SysNative\tasks\EasyBatteryManager" ["%ProgramFiles(x86)%\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe"] "C:\windows\SysNative\tasks\EasyDisplayMgr" ["C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe"] "C:\windows\SysNative\tasks\EasySpeedUpManager" ["%programfiles(x86)%\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe"] "C:\windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-543984391-606257222-1702330859-1005Core" [C:\Users\Doris\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-543984391-606257222-1702330859-1005UA" [C:\Users\Doris\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\windows\SysNative\tasks\Java Update Scheduler" [C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe] "C:\windows\SysNative\tasks\Norton Security Scan for PROSUP" [C:\Program Files (x86)\Norton Security Scan\Engine\2.7.3.34\Nss.exe] "C:\windows\SysNative\tasks\SamsungSupportCenter" [%programfiles(x86)%\Samsung\Samsung Support Center\SSCKbdHk.exe] "C:\windows\SysNative\tasks\SidebarExecute" [C:\Program Files\Windows Sidebar\sidebar.exe] "C:\windows\SysNative\tasks\SUPBackground" ["%ProgramFiles%\Samsung\Samsung Update Plus\SUPBackground.exe"] "C:\windows\SysNative\tasks\TuneUpUtilities_Task_BkGndMaintenance2012" [C:\Program Files (x86)\AVG\AVG PC TuneUp\OneClick.exe] "C:\windows\SysNative\tasks\User_Feed_Synchronization-{1C6EBE8D-BCEB-4696-B274-3B599963AB69}" [C:\windows\system32\msfeedssync.exe] "C:\windows\SysNative\tasks\User_Feed_Synchronization-{85FBBDC8-D7DB-4068-99CE-EF4610703628}" [C:\windows\system32\msfeedssync.exe] "C:\windows\SysNative\tasks\{96FAA4F2-DDB1-42F7-949C-874893F8696D}" [C:\Program Files (x86)\Skype\\Phone\Skype.exe] "C:\windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{FFB96CC1-7EB3-449D-B827-DB661701C6BB}"="C:\Program Files\CheckPoint\ZAForceField\TrustChecker" [] [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{FFB96CC1-7EB3-449D-B827-DB661701C6BB}"="C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker" [] ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions bodddioamolcibagionmmobehnbhiakf - C:\Program Files (x86)\BrowserCompanion\blabbers-ch.crx[] giacfgjdclhnmkacnfbaljbmpnelflol - C:\Program Files (x86)\iVIDI.org plugin\ividiplg.crx[] kpdhgpkkloealnjnmepfhanpcleldbef - C:\Program Files (x86)\Unitech LLC\ividi\1.8.23.0\ividi.crx[] ndibdjnfmopecpmkdieinmbadjfpblof - C:\ProgramData\AVG Nation toolbar\ChromeExt\18.1.0.443\avg.crx[] Google Docs - Doris\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - Doris\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - Doris\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Browser Companion Helper - Doris\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf Google Search - Doris\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf iVIDI.org plugin - Doris\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol iVidi Chrome Toolbar - Doris\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpdhgpkkloealnjnmepfhanpcleldbef AVG Nation Toolbar - Doris\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Gmail - Doris\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia YouTube - PROSUP\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Browser Companion Helper - PROSUP\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf Google Search - PROSUP\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf New Tab - PROSUP\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnpmlnedpdikbgdghljdepnljfpkhccn iVIDI.org plugin - PROSUP\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol iVidi Chrome Toolbar - PROSUP\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpdhgpkkloealnjnmepfhanpcleldbef AVG Nation Toolbar - PROSUP\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Gmail - PROSUP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Google Docs - William\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - William\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - William\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Browser Companion Helper - William\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf Google Search - William\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf iVIDI.org plugin - William\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol iVidi Chrome Toolbar - William\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpdhgpkkloealnjnmepfhanpcleldbef AVG Nation Toolbar - William\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Google Drive - CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Browser Companion Helper - CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf Google Search - CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Talking Tom Cat 2 - CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\djhilncnigiihpnfpeplmeahdhepcfpd Talking Tom Cat 3 - CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlkceknkhggbghojienjelijeeokoopi iVIDI.org plugin - CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol iVidi Chrome Toolbar - CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpdhgpkkloealnjnmepfhanpcleldbef Plants vs Zombies - CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcegpfdgcoclcdfkjahiimlikdpnina AVG Nation Toolbar - CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Gmail - CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Google Docs - CLIA~1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - CLIA~1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - CLIA~1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Browser Companion Helper - CLIA~1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bodddioamolcibagionmmobehnbhiakf Google Search - CLIA~1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Gmail - CLIA~1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== Chromium Startpages ====================== C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Preferences "homepage": "http://search.babylon.com/?affID=112059&tt=120912_ccp_3712_7&babsrc=HP_ss&mntrId=423561820000000000000015834010fe", "homepage": "http://search.babylon.com/?affID=112059&tt=120912_ccp_3712_7&babsrc=HP_ss&mntrId=423561820000000000000015834010fe", "urls_to_restore_on_startup": [ "http://www.google.be/" ] "urls_to_restore_on_startup": [ "http://www.google.be/" ] C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Preferences "homepage": "http://avg.nation.com/avgtbavg/search/home?cid={2FD10621-CC59-4B46-94BA-1D2E0747FD2B}&mid=728e77e77b2147d6ab0cd16d124294d4-171a3ff185b074c3d20e20e6b361da1708b5d0ef&lang=nl&ds=AVG&coid=avgtbavg&pr=fr&d=2013-09-25 18:52:44&v=18.1.0.443&pid=nation&sg=0&sap=hp", "homepage": "http://avg.nation.com/avgtbavg/search/home?cid={2FD10621-CC59-4B46-94BA-1D2E0747FD2B}&mid=728e77e77b2147d6ab0cd16d124294d4-171a3ff185b074c3d20e20e6b361da1708b5d0ef&lang=nl&ds=AVG&coid=avgtbavg&pr=fr&d=2013-09-25 18:52:44&v=18.1.0.443&pid=nation&sg=0&sap=hp", "urls_to_restore_on_startup": [ "https://www.google.be/" ] "urls_to_restore_on_startup": [ "https://www.google.be/" ] C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Preferences "homepage": "http://search.babylon.com/?affID=112059&tt=120912_ccp_3712_7&babsrc=HP_ss&mntrId=423561820000000000000015834010fe", "homepage": "http://search.babylon.com/?affID=112059&tt=120912_ccp_3712_7&babsrc=HP_ss&mntrId=423561820000000000000015834010fe", "urls_to_restore_on_startup": [ "http://search.babylon.com/?affID=112059&tt=120912_ccp_3712_7&babsrc=HP_ss&mntrId=423561820000000000000015834010fe", "http://isearch.avg.com/?cid={1FA3134B-D975-4860-95C4-6681CD5FABA7}&mid=ae7575f8924470943c4d1c5e5a200425-ff66f0c0184dea872057e96325a50d42ded11da7&lang=nl&ds=AVG&pr=fr&d=2011-12-08 12:45:37&v=14.0.2.14&pid=avg&sg=&sap=hp", "http://www.google.com", "http://isearch.avg.com/?cid={1FA3134B-D975-4860-95C4-6681CD5FABA7}&mid=ae7575f8924470943c4d1c5e5a200425-ff66f0c0184dea872057e96325a50d42ded11da7&lang=nl&ds=AVG&pr=fr&d=2011-12-08 12:45:37&v=15.4.0.5&pid=avg&sg=0&sap=hp" ] "urls_to_restore_on_startup": [ "http://search.babylon.com/?affID=112059&tt=120912_ccp_3712_7&babsrc=HP_ss&mntrId=423561820000000000000015834010fe", "http://isearch.avg.com/?cid={1FA3134B-D975-4860-95C4-6681CD5FABA7}&mid=ae7575f8924470943c4d1c5e5a200425-ff66f0c0184dea872057e96325a50d42ded11da7&lang=nl&ds=AVG&pr=fr&d=2011-12-08 12:45:37&v=14.0.2.14&pid=avg&sg=&sap=hp", "http://www.google.com", "http://isearch.avg.com/?cid={1FA3134B-D975-4860-95C4-6681CD5FABA7}&mid=ae7575f8924470943c4d1c5e5a200425-ff66f0c0184dea872057e96325a50d42ded11da7&lang=nl&ds=AVG&pr=fr&d=2011-12-08 12:45:37&v=15.4.0.5&pid=avg&sg=0&sap=hp" ] ==== Chrome Fix ====================== C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_toolbar.avg.com_0.localstorage deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_toolbar.avg.com_0.localstorage-journal deleted successfully C:\Users\Doris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully C:\Users\Doris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully C:\Users\Doris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully C:\Users\Doris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.babylon.com_0.localstorage deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.babylon.com_0.localstorage-journal deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.babylon.com_0.localstorage deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.babylon.com_0.localstorage-journal deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.babylon.com_0.localstorage deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.babylon.com_0.localstorage-journal deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_isearch.avg.com_0.localstorage deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_isearch.avg.com_0.localstorage-journal deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.avg.com_0.localstorage deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.avg.com_0.localstorage-journal deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.avg.com_0.localstorage deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.avg.com_0.localstorage-journal deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_nl.softonic.com_0.localstorage-journal deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_super-meat-boy.nl.softonic.com_0.localstorage deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_super-meat-boy.nl.softonic.com_0.localstorage-journal deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_gta-iv-san-andreas.en.softonic.com_0.localstorage deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_gta-iv-san-andreas.en.softonic.com_0.localstorage-journal deleted successfully C:\Users\Doris\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\bodddioamolcibagionmmobehnbhiakf deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bodddioamolcibagionmmobehnbhiakf deleted successfully C:\Users\Doris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bodddioamolcibagionmmobehnbhiakf_0.localstorage deleted successfully C:\Users\Doris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bodddioamolcibagionmmobehnbhiakf_0.localstorage-journal deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bodddioamolcibagionmmobehnbhiakf_0.localstorage deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bodddioamolcibagionmmobehnbhiakf_0.localstorage-journal deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bodddioamolcibagionmmobehnbhiakf_0.localstorage deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bodddioamolcibagionmmobehnbhiakf_0.localstorage-journal deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bodddioamolcibagionmmobehnbhiakf_0.localstorage deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bodddioamolcibagionmmobehnbhiakf_0.localstorage-journal deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_bodddioamolcibagionmmobehnbhiakf_0.localstorage deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_bodddioamolcibagionmmobehnbhiakf_0.localstorage-journal deleted successfully C:\Users\Doris\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpdhgpkkloealnjnmepfhanpcleldbef deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpdhgpkkloealnjnmepfhanpcleldbef deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpdhgpkkloealnjnmepfhanpcleldbef deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpdhgpkkloealnjnmepfhanpcleldbef deleted successfully C:\Users\Doris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kpdhgpkkloealnjnmepfhanpcleldbef_0.localstorage deleted successfully C:\Users\Doris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kpdhgpkkloealnjnmepfhanpcleldbef_0.localstorage-journal deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kpdhgpkkloealnjnmepfhanpcleldbef_0.localstorage deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kpdhgpkkloealnjnmepfhanpcleldbef_0.localstorage-journal deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kpdhgpkkloealnjnmepfhanpcleldbef_0.localstorage deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kpdhgpkkloealnjnmepfhanpcleldbef_0.localstorage-journal deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kpdhgpkkloealnjnmepfhanpcleldbef_0.localstorage deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kpdhgpkkloealnjnmepfhanpcleldbef_0.localstorage-journal deleted successfully C:\Users\Doris\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol deleted successfully C:\Users\Doris\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully C:\Users\Doris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndibdjnfmopecpmkdieinmbadjfpblof_0.localstorage deleted successfully C:\Users\Doris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndibdjnfmopecpmkdieinmbadjfpblof_0.localstorage-journal deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndibdjnfmopecpmkdieinmbadjfpblof_0.localstorage deleted successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndibdjnfmopecpmkdieinmbadjfpblof_0.localstorage-journal deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndibdjnfmopecpmkdieinmbadjfpblof_0.localstorage deleted successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndibdjnfmopecpmkdieinmbadjfpblof_0.localstorage-journal deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndibdjnfmopecpmkdieinmbadjfpblof_0.localstorage deleted successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ndibdjnfmopecpmkdieinmbadjfpblof_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://be.msn.com/?rd=1&ucc=BE&dcc=BE&opt=0" "Default_Page_URL"="http://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="http://be.msn.com/?rd=1&ucc=BE&dcc=BE&opt=0" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{67A2568C-7A0A-4EED-AECC-B5405DE63B64}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?FORM=WLETDF&PC=WLEM&q={searchTerms}&src=IE-SearchBox" {67A2568C-7A0A-4EED-AECC-B5405DE63B64} Google Url="http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN_nlBE410" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847} deleted successfully HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847} deleted successfully HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00cbb66b-1d3b-46d3-9577-323a336acb50} deleted successfully HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00cbb66b-1d3b-46d3-9577-323a336acb50} deleted successfully HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8B8B2E80-1444-451D-AC8E-EB9A847F3887} deleted successfully HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8B8B2E80-1444-451D-AC8E-EB9A847F3887} deleted successfully HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531} deleted successfully HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531} deleted successfully HKEY_CLASSES_ROOT\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{00cbb66b-1d3b-46d3-9577-323a336acb50} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00cbb66b-1d3b-46d3-9577-323a336acb50} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{8B8B2E80-1444-451D-AC8E-EB9A847F3887} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8B8B2E80-1444-451D-AC8E-EB9A847F3887} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{963B125B-8B21-49A2-A3A8-E37092276531} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531} deleted successfully HKEY_CLASSES_ROOT\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-543984391-606257222-1702330859-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{FFB96CC1-7EB3-449D-B827-DB661701C6BB} deleted successfully HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ClickPotatoLite@ClickPotatoLite.com deleted successfully ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B3FE01107D5856345B58C425C1AF0946 deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\EB6AF8AEEB922FA4392548F13812E50B deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B2FD9C0A5B9838449838816A28001F4B deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1EC4CB0D-3256-2F80-2D5A-21F295D7FC4A} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{368A7A2E-A955-DCBE-4DFD-6985BB88CE33} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\bodddioamolcibagionmmobehnbhiakf deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\giacfgjdclhnmkacnfbaljbmpnelflol deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\kpdhgpkkloealnjnmepfhanpcleldbef deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SkypEmoticons_is1 deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BrowserCompanion deleted successfully HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdater deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0110EF3B-85D7-4365-B585-4C521CFA9064} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Sweetpacks Bundle Uninstaller deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{A0C9DF2B-89B5-4483-8983-18A68200F1B4} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\B3FE01107D5856345B58C425C1AF0946 deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\EB6AF8AEEB922FA4392548F13812E50B deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\B2FD9C0A5B9838449838816A28001F4B deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ROC_roc_dec12 deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt deleted successfully ==== HijackThis Entries ====================== R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file) F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file) O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - (no file) O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file) O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - (no file) O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" O4 - HKLM\..\Run: [UpdatePDRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\7.0" O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe" O4 - HKLM\..\Run: [UpdatePPShortCut] "C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerProducer" UpdateWithCreateOnce "Software\CyberLink\PowerProducer\5.0" O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" O4 - HKLM\..\Run: [APLangApp] "C:\Program Files (x86)\AnyPC Client\APLangApp.exe" O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0" O4 - HKLM\..\Run: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe O4 - HKLM\..\Run: [Sweetpacks Communicator] C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Nation toolbar\vprot.exe" O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [bot.exe] G:\runescepe\bot.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun O4 - HKCU\..\Run: [se] "C:\Users\William\AppData\Roaming\SkypEmoticons\SE.exe" /minimized O4 - HKCU\..\Run: [Steam] "D:\staem\Steam.exe" -silent O4 - HKCU\..\Run: [RGSC] D:\Rockstar Games Social Club\RGSCLauncher.exe /silent O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - Startup: OpenOffice.org 3.2 .lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (file missing) O18 - Protocol: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (file missing) O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file) O18 - Protocol: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - C:\Program Files (x86)\BrowserCompanion\tdataprotocol.dll (file missing) O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.0\ViProtocol.dll (file missing) O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing) O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing) O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing) O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing) O23 - Service: Netlogon - Unknown owner - C:\windows\system32\lsass.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\windows\system32\nvvsvc.exe (file missing) O23 - Service: PnkBstrA - Unknown owner - C:\windows\system32\PnkBstrA.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing) O23 - Service: Rezip - Unknown owner - C:\windows\SysWOW64\Rezip.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing) O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Empty IE Cache ====================== C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Doris\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Doris\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Doris\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Doris\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\PROSUP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\PROSUP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\PROSUP\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\PROSUP\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\TEMP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\William\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\William\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\William\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\CLIA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\CLIA~1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\CLIA~1\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\CLIA~1\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\William\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\Doris\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\PROSUP\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\William\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\CLIA~1\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=6009 folders=885 855330232 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Doris\AppData\Local\Temp emptied successfully C:\Users\PROSUP\AppData\Local\Temp emptied successfully C:\Users\TEMP\AppData\Local\Temp emptied successfully C:\Users\William\AppData\Local\Temp will be emptied at reboot C:\Users\CLIA~1\AppData\Local\Temp emptied successfully C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\windows\Temp successfully emptied C:\Users\William\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\William\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found ==== EOF on za 16/08/2014 at 16:24:18,82 ======================