Zoek.exe v5.0.0.0 Updated 11-October-2014 Tool run by bryan on ma 13/10/2014 at 13:05:12,91. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\bryan\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 13/10/2014 13:07:56 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\RegClean Pro deleted successfully C:\PROGRA~2\Samsung deleted successfully C:\PROGRA~2\COMMON~1\SWF Studio deleted successfully C:\PROGRA~3\Allmyapps deleted successfully C:\PROGRA~3\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} deleted successfully C:\Users\bryan\AppData\Roaming\Advanced System Protector deleted successfully C:\Users\bryan\AppData\Roaming\Samsung deleted successfully C:\Users\bryan\AppData\Local\VirtualStore deleted successfully C:\Users\Gast\AppData\Local\VirtualStore deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-615066880-1160205500-775624097-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9598e82a-7e09-4438-b425-b9e9718c3c73} deleted successfully HKEY_USERS\S-1-5-21-615066880-1160205500-775624097-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9598e82a-7e09-4438-b425-b9e9718c3c73} deleted successfully HKEY_USERS\S-1-5-21-615066880-1160205500-775624097-1002\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully HKEY_USERS\S-1-5-21-615066880-1160205500-775624097-1002\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} deleted successfully HKEY_USERS\S-1-5-21-615066880-1160205500-775624097-1002\Software\Microsoft\Internet Explorer\SearchScopes\{BBCBAACF-8A56-4D5A-B780-2AAC2515056A} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{9598e82a-7e09-4438-b425-b9e9718c3c73} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9598e82a-7e09-4438-b425-b9e9718c3c73} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Running Processes ====================== C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe C:\Program Files (x86)\IObit\Start Menu 8\StartMenu_Hook.exe C:\Program Files (x86)\Appstein\bin\utilAppstein.exe C:\Program Files (x86)\Appstein\bin\Appstein.BrowserAdapter.exe C:\Program Files (x86)\glindorus\bin\utilglindorus.exe C:\Users\bryan\AppData\Local\Pay-By-Ads\Yahoo Search\1.3.12.4\dsrlte.exe C:\Program Files (x86)\glindorus\bin\glindorus.BrowserAdapter.exe C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe C:\Program Files (x86)\glindorus\bin\glindorus.BOASHelper.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe C:\Program Files (x86)\Appstein\updateAppstein.exe C:\Program Files (x86)\glindorus\updateglindorus.exe C:\Users\bryan\AppData\Local\Pay-By-Ads\Yahoo Search\1.3.12.4\dsrlte.exe C:\Program Files (x86)\glindorus\bin\glindorus.BOASPRT.exe C:\Program Files (x86)\glindorus\bin\glindorus.BOAS.exe C:\Users\bryan\Desktop\zoek.exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe C:\WINDOWS\SysWOW64\cmd.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update Appstein deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update Appstein deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update glindorus deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update glindorus deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util Appstein deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util Appstein deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util glindorus deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util glindorus deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BackupStack deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CltMngSvc deleted successfully ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}] [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9598e82a-7e09-4438-b425-b9e9718c3c73}] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe] ==== Deleting Files \ Folders ====================== C:\PROGRA~3\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} not found C:\PROGRA~2\Mobogenie deleted C:\PROGRA~2\Connected Music powered by Universal Music Group deleted C:\PROGRA~2\ASP deleted C:\PROGRA~2\Systweak Support Dock deleted C:\Users\bryan\AppData\Roaming\Tuneup Pro deleted C:\Users\bryan\AppData\Roaming\Allmyapps deleted C:\Users\bryan\AppData\Roaming\systweak deleted C:\PROGRA~3\Systweak deleted C:\PROGRA~3\systemk deleted C:\Users\bryan\AppData\Local\CrashRpt deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced-System Protector deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Systweak Support Dock deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\Users\bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup deleted C:\Users\bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk deleted C:\Users\bryan\AppData\LocalLow\DataMngr deleted C:\windows\SysNative\Tasks\Yahoo! Search deleted C:\windows\SysNative\Tasks\Yahoo! Search Udpater deleted C:\windows\SysNative\Tasks\LaunchSignup deleted C:\windows\SysNative\drivers\{26d264d2-014c-4f07-bf2c-ebf9aed40cef}Gw64.sys deleted C:\windows\SysNative\drivers\{26d264d2-014c-4f07-bf2c-ebf9aed40cef}w64.sys deleted C:\WINDOWS\SysNative\config\systemprofile\Searches deleted C:\WINDOWS\Syswow64\SearchProtect deleted C:\Users\bryan\Documents\Optimizer Pro deleted "C:\Users\bryan\AppData\Local\{9A0E04FF-DF73-4EBD-9661-F41197B48809}" deleted "C:\Program Files (x86)\glindorus\updateglindorus.exe" deleted "C:\Program Files (x86)\MyPC Backup\GetText.dll" deleted "C:\Program Files (x86)\MyPC Backup\MPCBClient.dll" deleted "C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe" deleted "C:\Program Files (x86)\MyPC Backup\ObjectListView.dll" deleted "C:\Program Files (x86)\MyPC Backup\Shared Stack.dll" deleted "C:\PROGRA~2\glindorus\updateglindorus.exe" deleted "C:\PROGRA~2\MyPC Backup\GetText.dll" deleted "C:\PROGRA~2\MyPC Backup\MPCBClient.dll" deleted "C:\PROGRA~2\MyPC Backup\MyPC Backup.exe" deleted "C:\PROGRA~2\MyPC Backup\ObjectListView.dll" deleted "C:\PROGRA~2\MyPC Backup\Shared Stack.dll" deleted "C:\PROGRA~2\glindorus\updateglindorus.exe" deleted "C:\Program Files (x86)\glindorus\bin\glindorus.BOAS.exe" deleted "C:\Program Files (x86)\glindorus\bin\glindorus.BOASHelper.exe" deleted "C:\Program Files (x86)\glindorus\bin\glindorus.BOASPRT.exe" deleted "C:\Program Files (x86)\glindorus\bin\glindorus.PurBrowse64.exe" deleted "C:\Program Files (x86)\glindorus\bin\utilglindorus.exe" deleted "C:\Users\bryan\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrlte.exe" deleted "C:\Program Files (x86)\MyPC Backup\x64\System.Data.SQLite.dll" deleted "C:\PROGRA~2\glindorus\bin\glindorus.BOAS.exe" deleted "C:\PROGRA~2\glindorus\bin\glindorus.BOASHelper.exe" deleted "C:\PROGRA~2\glindorus\bin\glindorus.BOASPRT.exe" deleted "C:\PROGRA~2\glindorus\bin\glindorus.PurBrowse64.exe" deleted "C:\PROGRA~2\glindorus\bin\utilglindorus.exe" deleted "C:\PROGRA~2\MyPC Backup\x64\System.Data.SQLite.dll" deleted "C:\PROGRA~2\Settings Manager\systemk\sysapcrt.dll" deleted "C:\PROGRA~2\Settings Manager\systemk\syskldr.dll" not deleted "C:\PROGRA~2\Settings Manager\systemk\systemk.dll" not deleted "C:\PROGRA~2\Settings Manager\systemk\systemkbho.dll" not deleted "C:\PROGRA~2\Settings Manager\systemk\x64\sysapcrt.dll" deleted "C:\PROGRA~2\Settings Manager\systemk\x64\syskldr.dll" not deleted "C:\PROGRA~2\Settings Manager\systemk\x64\systemk.dll" not deleted "C:\PROGRA~2\Settings Manager\systemk\x64\systemkbho.dll" not deleted "C:\Users\bryan\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrlte.exe" deleted "C:\PROGRA~2\glindorus\bin\glindorus.BOAS.exe" deleted "C:\PROGRA~2\glindorus\bin\glindorus.BOASHelper.exe" deleted "C:\PROGRA~2\glindorus\bin\glindorus.BOASPRT.exe" deleted "C:\PROGRA~2\glindorus\bin\glindorus.PurBrowse64.exe" deleted "C:\PROGRA~2\glindorus\bin\utilglindorus.exe" deleted "C:\Program Files (x86)\glindorus" not deleted "C:\Users\bryan\AppData\Local\Pay-By-Ads" deleted "C:\Program Files (x86)\MyPC Backup" not deleted "C:\PROGRA~2\glindorus" not deleted "C:\PROGRA~2\MyPC Backup" not deleted "C:\PROGRA~2\Settings Manager" not deleted "C:\Users\bryan\AppData\Local\Pay-By-Ads" deleted "C:\PROGRA~2\glindorus" not deleted "C:\Program Files (x86)\glindorus\bin" not deleted "C:\Users\bryan\AppData\Local\Pay-By-Ads\Yahoo! Search" deleted "C:\Users\bryan\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4" deleted "C:\Program Files (x86)\MyPC Backup\Database" not deleted "C:\Program Files (x86)\MyPC Backup\x64" not deleted "C:\PROGRA~2\glindorus\bin" not deleted "C:\PROGRA~2\MyPC Backup\Database" not deleted "C:\PROGRA~2\MyPC Backup\x64" not deleted "C:\PROGRA~2\Settings Manager\systemk" not deleted "C:\PROGRA~2\Settings Manager\systemk\x64" not deleted "C:\Users\bryan\AppData\Local\Pay-By-Ads\Yahoo! Search" deleted "C:\Users\bryan\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4" deleted "C:\PROGRA~2\glindorus\bin" not deleted ==== System Specs ====================== Windows: Windows Version 6.2 (Build 9200) Memory (RAM): 3683 MB CPU Info: AMD E1-1200 APU with Radeon(tm) HD Graphics CPU Speed: 1431,5 MHz Sound Card: Luidsprekers (Realtek High Defi | Display Adapters: AMD Radeon HD 7310 Graphics | AMD Radeon HD 7310 Graphics Monitors: 1x; Generic PnP Monitor | Screen Resolution: 1366 X 768 - 32 bit Network: Network Present Network Adapters: Microsoft Wi-Fi Direct Virtual Adapter | Ralink RT5390R 802.11bgn Wi-Fi Adapter CD / DVD Drives: 1x (E: | ) E: hp CDDVDW SN-208DB Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 16 Button Wheel Mouse Present Hard Disks: C: 282,1GB | D: 14,9GB Hard Disks - Free: C: 216,5GB | D: 1,9GB Manufacturer *: Insyde BIOS Info: AT/AT COMPATIBLE | | HPQOEM - 1 Time Zone: Romance (standaardtijd) Motherboard *: Hewlett-Packard 1885 Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: Windows Defender On-access scanning disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Internet Explorer Version: 11.0.9600.17278 Google Chrome version: 37.0.2062.124 Adobe Reader version: 11.0.9.29 Sun Java version: 1.7.0_21 (32-bit) Shockwave Player version: 11.6.6r636 ==== Files Recently Created / Modified ====================== ====== C:\WINDOWS ==== 2014-09-15 09:44:03 ACDBE1ED38167C8B01B8F63161BB2CEA 2374784 ----a-w- C:\WINDOWS\explorer.exe ====== C:\Users\bryan\AppData\Local\Temp ==== ====== Java Cache ===== ====== C:\WINDOWS\SysWOW64 ===== ====== C:\WINDOWS\SysWOW64\drivers ===== ====== C:\WINDOWS\Sysnative ===== ====== C:\WINDOWS\Sysnative\drivers ===== 2014-09-15 09:42:04 FEBAA7D782E30882FFF1CBCBBE8AD467 2515264 ----a-w- C:\WINDOWS\Sysnative\drivers\tcpip.sys 2014-09-15 09:41:49 6416E79A58A8FCC33A447A4DDDD3BF04 412160 ----a-w- C:\WINDOWS\Sysnative\drivers\srv.sys 2014-09-15 09:40:54 038C77D577900EE39410662478BB0D50 2009920 ----a-w- C:\WINDOWS\Sysnative\drivers\ntfs.sys 2014-09-15 09:40:42 5BED3AB69797C8786EF70AEA8C33748B 674816 ----a-w- C:\WINDOWS\Sysnative\drivers\srv2.sys 2014-09-15 09:40:33 77E1D08EF3BFB923F2EDC3FC8089E08E 475968 ----a-w- C:\WINDOWS\Sysnative\drivers\netio.sys 2014-09-15 09:40:23 240C5C3793206725AA05665851E8C214 412992 -c--a-w- C:\WINDOWS\Sysnative\drivers\spaceport.sys 2014-09-15 09:40:20 FF78D053A05E5A394F4E3C1816CC65A8 143680 -c--a-w- C:\WINDOWS\Sysnative\drivers\usbccgp.sys 2014-09-15 09:40:19 64CA2B4A49A8EAF495E435623ECCE7DB 310080 -c--a-w- C:\WINDOWS\Sysnative\drivers\volsnap.sys 2014-09-15 09:40:11 65392F3F3F65E4C6CC82A0F4F8A0B051 468288 -c--a-w- C:\WINDOWS\Sysnative\drivers\USBHUB3.SYS 2014-09-15 09:39:47 D047CD668E6277FD80F0C613946F034C 246272 ----a-w- C:\WINDOWS\Sysnative\drivers\srvnet.sys 2014-09-15 09:39:43 26ACA481FAFEC59FE311D719E3027BBA 446976 ----a-w- C:\WINDOWS\Sysnative\drivers\nwifi.sys 2014-09-15 09:39:40 FEF0BC107812B36849741C3211BA6B60 419648 -c--a-w- C:\WINDOWS\Sysnative\drivers\usbhub.sys 2014-09-15 09:39:30 9C096BF5E10CA8BFA56F32522A89FAF1 79872 ----a-w- C:\WINDOWS\Sysnative\drivers\IPMIDrv.sys 2014-09-15 09:39:24 E4B4BE2D7750849C07589DA0B0AABA01 1118040 ----a-w- C:\WINDOWS\Sysnative\drivers\ndis.sys 2014-09-15 09:39:23 E0927EFA25D473367C3341B9F5969779 115712 ----a-w- C:\WINDOWS\Sysnative\drivers\bridge.sys 2014-09-15 09:39:23 D4B7ED39C7900384D9E5C1283F1E7926 76800 -c--a-w- C:\WINDOWS\Sysnative\drivers\hdaudbus.sys 2014-09-15 09:39:23 C910E5D18958914A66F0E45689D0B40A 206848 ----a-w- C:\WINDOWS\Sysnative\drivers\mrxsmb20.sys 2014-09-15 09:39:23 B1AA3B19A2E596A59224F893E01A5A75 126464 ----a-w- C:\WINDOWS\Sysnative\drivers\NdisImPlatform.sys 2014-09-15 09:39:18 91ED124E261EA8FAA1C0FFDF2A71B0C4 280384 -c--a-w- C:\WINDOWS\Sysnative\drivers\pci.sys 2014-09-15 09:39:18 1DD05F4857C2188744B9E864658949DD 295424 ----a-w- C:\WINDOWS\Sysnative\drivers\ks.sys 2014-09-15 09:36:44 8DF1254093B5C354CE725EB6B9B0DE19 146752 ----a-w- C:\WINDOWS\Sysnative\drivers\msgpioclx.sys ====== C:\WINDOWS\Tasks ====== ====== C:\WINDOWS\Temp ====== ======= C:\Program Files ===== 2014-10-10 18:32:54 -------- d-----w- C:\Program Files\trend micro ======= C:\PROGRA~2 ===== 2014-10-08 15:39:55 -------- d-----w- C:\PROGRA~2\Tuneup Pro ======= C: ===== ====== C:\Users\bryan\AppData\Roaming ====== 2014-10-13 11:33:34 -------- d-----w- C:\Users\bryan\AppData\Locallow\DataMngr ====== C:\Users\bryan ====== 2014-10-09 07:56:03 -------- d-----w- C:\WINDOWS\serviceprofiles\Localservice\winhttp 2014-09-24 11:26:15 02C1EE40968BAA67C3A785CDA9807125 262 --sha-r- C:\ProgramData\ntuser.pol ====== C: exe-files == 2014-10-13 11:34:18 C45895307DB44CBDD2A83E234EB18F42 1786656 ----a-w- C:\Program Files (x86)\glindorus\bin\glindorus.BOASPRT.exe 2014-10-13 11:34:17 FEEB7579B4FE0F649DCE4C83A41E6322 1649952 ----a-w- C:\Program Files (x86)\glindorus\bin\glindorus.BOASHelper.exe 2014-10-13 11:34:16 8D34AE075F977881FC20F4A0D64F4899 1791264 ----a-w- C:\Program Files (x86)\glindorus\bin\glindorus.BOAS.exe 2014-10-13 11:34:10 F36EBF41FE3C19A9762EAD59E8E2CEB5 98592 ----a-w- C:\Program Files (x86)\glindorus\bin\glindorus.BrowserAdapter.exe 2014-10-13 11:34:10 58D75596D49844CD82263CA5C49DBDB8 114976 ----a-w- C:\Program Files (x86)\glindorus\bin\glindorus.BrowserAdapter64.exe 2014-10-10 18:32:55 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\bryan.exe 2014-10-10 18:32:44 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\bryan\AppData\Local\Microsoft\Windows\INetCache\IE\GO90JUDP\RSITx64.exe === C: other files == 2014-10-13 11:34:16 5D495A9BE30FF6D753298A2BC15E184C 2411856 ----a-w- C:\Program Files (x86)\glindorus\bin\glindorus.BOAS.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-615066880-1160205500-775624097-1002\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "Yahoo\Users\bryan\AppData\Local\Pay-By-Ads\Yahoo Search\1.3.12.4\dsrlte.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun" "CLVirtualDrive"="C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe /R" "RemoteControl10"="C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" "HP Quick Launch"="C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "Yahoo\Users\bryan\AppData\Local\Pay-By-Ads\Yahoo Search\1.3.12.4\dsrlte.exe" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s" "Classic Start Menu"="C:\Program Files\Classic Shell\ClassicStartMenu.exe -autorun" "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe " [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "NCPluginUpdater"="C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe Update" ==== Task Scheduler Jobs ====================== C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [29/04/2013 10:46] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [29/04/2013 10:46] C:\WINDOWS\tasks\HPCeeScheduleForbryan.job --a-------- [Undetermined Task] C:\WINDOWS\tasks\Synaptics TouchPad Enhancements.job --a-------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [29/10/2013 20:33] ==== Other Scheduled Tasks ====================== "C:\WINDOWS\SysNative\tasks\bureau" [explorer] "C:\WINDOWS\SysNative\tasks\CLMLSvc_P2G8" [C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe] "C:\WINDOWS\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\BrowserChoice\browserchoice.exe] "C:\WINDOWS\SysNative\tasks\desktop" [explorer] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\WINDOWS\SysNative\tasks\HPCeeScheduleForbryan" [C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe] "C:\WINDOWS\SysNative\tasks\MirageAgent" [C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe] "C:\WINDOWS\SysNative\tasks\naarbureaublad" [C:\Users\bryan\Documents\bootdesktop.scf] "C:\WINDOWS\SysNative\tasks\StartMenuAutoupdate" [C:\Program Files (x86)\IObit\Start Menu 8\AutoUpdate.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\Update Check" [C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] "C:\WINDOWS\SysNative\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe] ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions icmlaeflemplmjndnaapfdbbnpncnbda - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[] llmcibonccojooiboenghfafpieoabpl - C:\Program Files (x86)\glindorus\llmcibonccojooiboenghfafpieoabpl.crx[] Google Docs - bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake Appstein - bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\glhcikafncjeoaofomdjpnmjkfmhghlb glindorus - bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\llmcibonccojooiboenghfafpieoabpl Google Wallet - bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda ==== Chromium Fix ====================== C:\Users\bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\llmcibonccojooiboenghfafpieoabpl deleted successfully C:\Users\bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_llmcibonccojooiboenghfafpieoabpl_0.localstorage deleted successfully C:\Users\bryan\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\llmcibonccojooiboenghfafpieoabpl deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://rts.dsrlte.com?affID=kb37_625B6BF7-6F31-4706-A0C3-6962BD00FEE2" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://rts.dsrlte.com?affID=kb37_625B6BF7-6F31-4706-A0C3-6962BD00FEE2" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CPNTDFJS" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7SAVT_nlBE534" {D944BB61-2E34-4DBF-A683-47E505C587DC} eBay Url="http://rover.ebay.com/rover/1/1553-29906-12136-18/4" ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\llmcibonccojooiboenghfafpieoabpl deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Settings Manager deleted successfully ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [CLVirtualDrive] "C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [Yahoo! Search] C:\Users\bryan\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.12.4\dsrlte.exe O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing) O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: Google Update-service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: StartMenu8 Service (StartMenuService) - IObit - C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\bryan\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\bryan\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\Users\Gast\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\bryan\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=1118 folders=184 322446088 bytes) ==== Empty Temp Folders ====================== C:\Users\bryan\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Gast\AppData\Local\Temp emptied successfully C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\bryan\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\PROGRA~2\Settings Manager\systemk\syskldr.dll" not found "C:\PROGRA~2\Settings Manager\systemk\systemk.dll" not found "C:\PROGRA~2\Settings Manager\systemk\systemkbho.dll" not found "C:\PROGRA~2\Settings Manager\systemk\x64\syskldr.dll" not found "C:\PROGRA~2\Settings Manager\systemk\x64\systemk.dll" not found "C:\PROGRA~2\Settings Manager\systemk\x64\systemkbho.dll" not found "C:\Program Files (x86)\glindorus" not found "C:\Program Files (x86)\MyPC Backup" not found "C:\PROGRA~2\glindorus" not found "C:\PROGRA~2\MyPC Backup" not found "C:\PROGRA~2\Settings Manager" not found "C:\PROGRA~2\glindorus" not found ==== EOF on ma 13/10/2014 at 13:56:37,57 ======================