Zoek.exe v5.0.0.0 Updated 08-November-2014 Tool run by marre on zo 09/11/2014 at 14:17:57,68. Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\marre\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 9/11/2014 14:24:38 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\Hewlett-Packard deleted successfully C:\PROGRA~2\MSXML 4.0 deleted successfully C:\PROGRA~2\COMMON~1\Symantec Shared deleted successfully C:\Program Files\Google deleted successfully C:\PROGRA~3\Babylon deleted successfully C:\PROGRA~3\Oracle deleted successfully C:\PROGRA~3\Roxio deleted successfully C:\PROGRA~3\System32 deleted successfully C:\Users\Gast\AppData\Roaming\iolo deleted successfully C:\Users\marre\AppData\Roaming\msnmsgr deleted successfully C:\Users\marre\AppData\Roaming\PeerNetworking deleted successfully C:\Users\marre\AppData\Roaming\Recordpad deleted successfully C:\Users\marre\AppData\Roaming\Systweak deleted successfully C:\Users\marre\AppData\Roaming\Windows Live Writer deleted successfully C:\Users\Gast\AppData\Local\VirtualStore deleted successfully C:\Users\marre\AppData\Local\Conduit deleted successfully C:\Users\marre\AppData\Local\DataSafeOnline deleted successfully C:\Users\marre\AppData\Local\PackageAware deleted successfully C:\Users\marre\AppData\Local\VMware deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3209196207-3559708430-3916157165-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A} deleted successfully HKEY_USERS\S-1-5-21-3209196207-3559708430-3916157165-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} deleted successfully HKEY_USERS\S-1-5-21-3209196207-3559708430-3916157165-1000\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} deleted successfully HKEY_USERS\S-1-5-21-3209196207-3559708430-3916157165-1000\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} deleted successfully HKEY_USERS\S-1-5-21-3209196207-3559708430-3916157165-1000\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e} deleted successfully HKEY_USERS\S-1-5-21-3209196207-3559708430-3916157165-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} deleted successfully HKEY_USERS\S-1-5-21-3209196207-3559708430-3916157165-1000\Software\Microsoft\Internet Explorer\SearchScopes\{ADE90855-7A5C-49CF-BE64-DC565A0A90CC} deleted successfully HKEY_USERS\S-1-5-21-3209196207-3559708430-3916157165-1000\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} deleted successfully HKEY_USERS\S-1-5-21-3209196207-3559708430-3916157165-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\marre\AppData\Roaming\Mozilla\Firefox\Profiles\extensions user.js not found ---- FireFox user.js and prefs.js backups ---- prefs_20140911_1518_.backup ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] ""=- [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DATAMNGR] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dxtory Update Checker 2.0] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- ==== Deleting Files \ Folders ====================== C:\Program Files (x86)\Ask.com not found C:\Users\marre\Videos\Tochmaarappelsmetperen not found C:\Program Files (x86)\Common Files\Spigot\Search Settings not found C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 deleted C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 deleted C:\PROGRA~2\Mozilla Firefox\user.js deleted C:\PROGRA~2\DealPly deleted C:\PROGRA~2\FoxTabPDFReader deleted C:\PROGRA~2\COMMON~1\DVDVideoSoft\TB deleted C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted C:\PROGRA~2\iLivid deleted C:\PROGRA~2\Gophoto.it deleted C:\PROGRA~2\Perion deleted C:\PROGRA~2\Conduit deleted C:\user.js deleted C:\Users\marre\AppData\Roaming\DVDVideoSoftIEHelpers deleted C:\Users\marre\AppData\Roaming\Babylon deleted C:\Users\marre\AppData\Roaming\OpenCandy deleted C:\PROGRA~3\Ask deleted C:\PROGRA~3\boost_interprocess deleted C:\PROGRA~3\Tarma Installer deleted C:\Users\marre\AppData\Local\Ilivid Player deleted C:\Users\marre\AppData\Local\CRE deleted C:\Users\marre\AppData\Local\iMesh deleted C:\Users\marre\AppData\Local\Smartbar deleted C:\Users\marre\AppData\Local\Babylon deleted C:\Windows\SysNative\roboot64.exe deleted C:\Users\marre\AppData\LocalLow\BabylonToolbar deleted C:\Users\marre\AppData\LocalLow\boost_interprocess deleted C:\Users\marre\AppData\LocalLow\searchquband deleted C:\Users\marre\AppData\LocalLow\Funmoods deleted C:\Users\marre\AppData\LocalLow\Softonic deleted C:\Users\marre\AppData\LocalLow\DataMngr deleted C:\Users\marre\AppData\LocalLow\Incredibar.com deleted C:\Users\marre\AppData\LocalLow\PriceGong deleted C:\Users\marre\AppData\LocalLow\Conduit deleted C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Application Updater deleted C:\Windows\Syswow64\WNLT deleted C:\windows\SysNative\GroupPolicy\Machine deleted C:\windows\SysNative\GroupPolicy\User deleted C:\windows\SysNative\GroupPolicy\gpt.ini deleted C:\Users\marre\AppData\Roaming\MCsMUdPZo.exe deleted C:\Users\marre\AppData\Roaming\MIeCZtZKo.exe deleted C:\Users\marre\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\OneClickDownload@OneClickDownload.com deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\marre\AppData\Local\Temp ==== 2014-11-08 16:01:20 4885E1BF1971C8FA9E7686FD5199F500 26856 ----a-w- C:\Users\marre\AppData\Local\Temp\cpuz136\cpuz136_x64.sys ====== Java Cache ===== 2014-11-08 10:02:53 415FC9732A3F4D89A0E01251CD66E136 646 ----a-w- C:\Users\marre\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\40828621-44646b4f ====== C:\Windows\SysWOW64 ===== 2014-10-31 14:58:54 341AF37351A69534645C8F98241ACDF6 63568 ----a-w- C:\Windows\SysWOW64\vsocklib.dll 2014-10-31 14:33:20 7EEBDDF76D013181E21592D2FFD66A98 359128 ----a-w- C:\Windows\SysWOW64\vmnetdhcp.exe 2014-10-31 14:33:12 295010C3EDECCAF760853544D0C92C03 437976 ----a-w- C:\Windows\SysWOW64\vmnat.exe 2014-10-31 14:20:47 0A22F4EC42AF96EB33825E85DA9216F9 1024 ----a-w- C:\Windows\SysWOW64\%TMP% ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-10-31 14:58:54 9B8F9FE94C614E90908CC2B8D4184939 67664 ----a-w- C:\Windows\Sysnative\vsocklib.dll 2014-10-31 14:31:15 2EB4C558A4F8527D9B75715DF6AF2A55 931032 ----a-w- C:\Windows\Sysnative\vnetlib64.dll 2014-10-29 14:00:52 BF6EDE135E8A029F5F61B2DE56DEA7BA 49232 ----a-w- C:\Windows\Sysnative\vnetinst.dll 2014-10-29 14:00:52 195D45D9972BD2D8666FF7B3BF58CB1A 80464 ----a-w- C:\Windows\Sysnative\vmnetbridge.dll ====== C:\Windows\Sysnative\drivers ===== 2014-10-31 14:58:52 CB4D2E3C5E8BFA3CF6AFFF6DDC6CC70D 73296 ----a-w- C:\Windows\Sysnative\drivers\vsock.sys 2014-10-31 14:55:55 3459BF60AA9B66E308A3D1656AEFD6C3 64728 ----a-w- C:\Windows\Sysnative\drivers\vmx86.sys 2014-10-31 14:33:08 0554C979222692C8DB07AF39279EC67D 31448 ----a-w- C:\Windows\Sysnative\drivers\vmnetuserif.sys 2014-10-31 14:24:39 BDDBCFF870442B3C24C158CD53079132 54464 ----a-w- C:\Windows\Sysnative\drivers\hcmon.sys 2014-10-29 14:00:52 9E12C27C63A3DEB2DCAECB281461437B 24656 ----a-w- C:\Windows\Sysnative\drivers\vmnet.sys 2014-10-29 14:00:52 18AA5F4A3B1204AD00045EE5AD39BCDB 20560 ----a-w- C:\Windows\Sysnative\drivers\vmnetadapter.sys 2014-10-29 14:00:52 04CD4347CD9E8C40F78AD51F7FF426D0 46160 ----a-w- C:\Windows\Sysnative\drivers\vmnetbridge.sys 2014-10-19 01:34:01 1E34B436811CCA4A2783C0BC7A0BEB2E 198656 ----a-w- C:\Windows\Sysnative\drivers\fastfat.sys ====== C:\Windows\Tasks ====== 2014-10-13 18:10:34 6402E81D4A057B825E8AA0BFF51F162B 3136 ----a-w- C:\Windows\Sysnative\Tasks\PCDoctorBackgroundMonitorTask-Retry ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-11-08 21:23:15 -------- d-----w- C:\Program Files\trend micro 2014-11-08 16:00:50 -------- d-----w- C:\Program Files\Speccy 2014-11-05 12:24:28 -------- d-----w- C:\Program Files\iPod 2014-11-05 12:24:24 -------- d-----w- C:\Program Files\iTunes 2014-10-31 14:20:15 -------- d-----w- C:\Program Files\Common Files\VMware ======= C:\PROGRA~2 ===== 2014-11-05 12:24:24 -------- d-----w- C:\PROGRA~2\iTunes 2014-10-31 14:17:20 -------- d-----w- C:\PROGRA~2\COMMON~1\VMware 2014-10-31 14:17:14 -------- d-----w- C:\PROGRA~2\VMware 2014-10-18 15:23:50 -------- d-----w- C:\PROGRA~2\COMMON~1\Java ======= C: ===== ====== C:\Users\marre\AppData\Roaming ====== 2014-11-08 16:23:29 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\PnrpSqm 2014-11-08 16:01:33 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Roaming\PeerNetworking 2014-10-31 15:42:41 -------- d-----w- C:\Users\marre\AppData\Roaming\VMware 2014-10-31 14:59:06 -------- d-----w- C:\Windows\SysNative\config\systemprofile\AppData\Roaming\VMware 2014-10-31 14:59:00 -------- d-----w- C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\VMware 2014-10-31 14:14:51 3FDEA253411A2228EA17D723C6C85E7E 419262 ----a-w- C:\Users\marre\AppData\Local\dd_vcredistMSI03F5.txt 2014-10-31 14:14:50 7501EEBD6AE0F90D176C1E1913F05E78 13260 ----a-w- C:\Users\marre\AppData\Local\dd_vcredistUI03F5.txt 2014-10-31 14:13:39 8F7A1A7F22C24F8C396757009FA94E46 423518 ----a-w- C:\Users\marre\AppData\Local\dd_vcredistMSI030A.txt 2014-10-31 14:13:38 AAB2DFC648762D11D364944D67C9F0A8 13244 ----a-w- C:\Users\marre\AppData\Local\dd_vcredistUI030A.txt ====== C:\Users\marre ====== 2014-11-08 21:21:49 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\marre\Desktop\RSITx64.exe 2014-11-08 21:20:42 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\marre\Downloads\RSITx64.exe 2014-11-08 15:57:18 6DC6EBDF9391271098C40F6BA7779430 4890736 ----a-w- C:\Users\marre\Downloads\spsetup126.exe 2014-11-05 12:26:25 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2014-10-31 14:20:17 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware 2014-10-31 14:17:19 -------- d-----w- C:\Users\Public\Documents\Shared Virtual Machines 2014-10-31 14:17:19 -------- d-----w- C:\ProgramData\VMware 2014-10-31 14:07:36 6EBD748DFBF2759F24E8512CDCC31E41 514992056 ----a-w- C:\Users\marre\Downloads\VMware-workstation-full-10.0.4-2249910.exe ====== C: exe-files == 2014-11-08 21:23:15 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\marre.exe 2014-11-08 21:21:49 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\marre\Desktop\RSITx64.exe 2014-11-08 21:20:42 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\marre\Downloads\RSITx64.exe 2014-11-08 15:57:18 6DC6EBDF9391271098C40F6BA7779430 4890736 ----a-w- C:\Users\marre\Downloads\spsetup126.exe 2014-11-05 12:10:28 2BF25BB82936758771C99A2C70754E09 77104 ----a-w- C:\ProgramData\Apple Computer\Installer Cache\iTunes 12.0.1.26\SetupAdmin.exe === C: other files == 2014-11-08 16:01:20 4885E1BF1971C8FA9E7686FD5199F500 26856 ----a-w- C:\Users\marre\AppData\Local\Temp\cpuz136\cpuz136_x64.sys 2014-11-05 12:13:33 396E081A7A3E0C79EA1B17841C918DA4 14431 ----a-w- C:\Users\marre\Downloads\berichten.zip ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="rundll32.exe oobefldr.dll,ShowWelcomeCenter" "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /detectMem" [HKEY_USERS\S-1-5-21-3209196207-3559708430-3916157165-1000\Software\iolo\PC TuneUp\Startup Manager\Configuration\Disabled\Registry\HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Java\jre6\bin\jusched.exe" [HKEY_USERS\S-1-5-21-3209196207-3559708430-3916157165-1000\Software\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="C:\Windows\ehome\ehTray.exe" "Spotify Web Helper"="C:\Users\marre\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "Epson Stylus Photo PX720WD(Netwerk)"="C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGYE.EXE /FU C:\Windows\TEMP\E_S44DE.tmp /EF HKCU" "DellSystemDetect"="C:\Users\marre\AppData\Local\Apps\2.0\RX921DWY.0WY\1K6N0EAK.572\dell..tion_0f612f649c4a10af_0005.0007_59de4fd2458fcaec\DellSystemDetect.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun" "hpqSRMon"="C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" "Adobe Reader Speed Launcher"="C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "vmware-tray.exe"="C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="C:\Windows\ehome\ehTray.exe" "Spotify Web Helper"="C:\Users\marre\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" "Epson Stylus Photo PX720WD(Netwerk)"="C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGYE.EXE /FU C:\Windows\TEMP\E_S44DE.tmp /EF HKCU" "DellSystemDetect"="C:\Users\marre\AppData\Local\Apps\2.0\RX921DWY.0WY\1K6N0EAK.572\dell..tion_0f612f649c4a10af_0005.0007_59de4fd2458fcaec\DellSystemDetect.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=" " ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="C:\Program Files\DellTPad\Apoint.exe" "Dell DataSafe Online"="C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe /m" "MSC"="C:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey" "SysTrayApp"="%ProgramFiles%\IDT\WDM\sttray64.exe " ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AdobeAAMUpdater-1.0] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="AdobeAAMUpdater-1.0" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\OOBE\\PDApp\\UWA\\UpdaterStartupUtility.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AdobeCS5.5ServiceManager] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="AdobeCS5.5ServiceManager" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\CS5.5ServiceManager\\CS5.5ServiceManager.exe\" -launchedbylogin" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\APSDaemon] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="APSDaemon" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Dell DataSafe Online] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Dell DataSafe Online" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Dell DataSafe Online\\DataSafeOnline.exe\" /m" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Dell PC TuneUp Startup] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Dell PC TuneUp Startup" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\iolo\\Common\\Lib\\ioloLManager.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Dell Webcam Central] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Dell Webcam Central" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Dell Webcam\\Dell Webcam Central\\WebcamDell.exe\" /mode2" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DivXUpdate] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="DivXUpdate" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\DivX\\DivX Update\\DivXUpdate.exe\" /CHECKNOW" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Google Update] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Google Update" "hkey"="HKCU" "command"="\"C:\\Users\\marre\\AppData\\Local\\Google\\Update\\GoogleUpdate.exe\" /c" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HP Software Update] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HP Software Update" "hkey"="HKLM" "command"="C:\\Program Files (x86)\\HP\\HP Software Update\\HPWuSchd2.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iTunesHelper] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="iTunesHelper" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\iTunes\\iTunesHelper.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\LogMeIn Hamachi Ui] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="LogMeIn Hamachi Ui" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\LogMeIn Hamachi\\hamachi-2-ui.exe\" --auto-start" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\msnmsgr] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="msnmsgr" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Windows Live\\Messenger\\msnmsgr.exe\" /background" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PCMService] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PCMService" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Dell\\MediaDirect\\PCMService.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="QuickTime Task" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\QuickTime\\QTTask.exe\" -atboottime" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Recordpad] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Recordpad" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\NCH Software\\Recordpad\\recordpad.exe\" -logon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RMAlert] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RMAlert" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\PC Tools Registry Mechanic\\Alert.exe\" /PRODUCT=RM /R" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Sidebar] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Sidebar" "hkey"="HKCU" "command"="C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SightSpeed] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SightSpeed" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Dell Video Chat\\DellVideoChat.exe\" -bootmode" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Skype] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Skype" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Skype\\Phone\\Skype.exe\" /minimized /regrun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Spotify] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Spotify" "hkey"="HKCU" "command"="\"C:\\Users\\marre\\AppData\\Roaming\\Spotify\\Spotify.exe\" /uri spotify:autostart" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SSDMonitor] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SSDMonitor" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\PC Tools\\sMonitor\\SSDMonitor.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SunJavaUpdateSched" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\swg] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="swg" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SwitchBoard] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SwitchBoard" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Common Files\\Adobe\\SwitchBoard\\SwitchBoard.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\VitaDock] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="VitaDock" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\VitaDock\\VitaDock.exe\" /minimized" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Windows Defender] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Windows Defender" "hkey"="HKLM" "command"="%ProgramFiles%\\Windows Defender\\MSASCui.exe -hide" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Philips SA19xx Apparaatbeheer.lnk] "item"="Philips SA19xx Apparaatbeheer" "path"="C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Philips SA19xx Apparaatbeheer.lnk" "backup"="C:\\Windows\\pss\\Philips SA19xx Apparaatbeheer.lnk.CommonStartup" "backupExtension"=".CommonStartup" "command"="C:\\PROGRA~2\\Philips\\GOGEAR~1\\main.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^marre^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CaptureWiz.lnk] "item"="CaptureWiz" "path"="C:\\Users\\marre\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\CaptureWiz.lnk" "backup"="C:\\Windows\\pss\\CaptureWiz.lnk.Startup" "backupExtension"=".Startup" "command"="C:\\Users\\marre\\DOWNLO~1\\Pro\\CAPTUR~1.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^marre^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk] "item"="Dell Dock" "path"="C:\\Users\\marre\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Dell Dock.lnk" "backup"="C:\\Windows\\pss\\Dell Dock.lnk.Startup" "backupExtension"=".Startup" "command"="C:\\PROGRA~1\\Dell\\DellDock\\DellDock.exe" ==== Startup Folders ====================== 2009-04-22 21:42:54 1835 ----a-w- C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk 2009-04-22 21:42:54 1835 ----a-w- C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk 2011-03-20 19:28:19 1835 ----a-w- C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk 2013-03-06 16:53:27 1147 ----a-w- C:\Users\marre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Schermopname en Snel starten.lnk 2009-04-22 20:54:09 743 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk 2009-05-01 09:47:15 2004 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk 2009-04-22 20:58:26 1929 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [25/10/2014 09:39] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [25/10/2014 09:39] C:\Windows\tasks\WebReg HP Deskjet F2200 series.job --a------ C:\Program Files (x86)\HP\Digital Imaging\bin\hpqwrg.exe [14/10/2007 19:40] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\PCDEventLauncherTask" ["C:\Program Files\My Dell\sessionchecker.exe"] "C:\Windows\SysNative\tasks\PCDoctorBackgroundMonitorTask" ["C:\Program Files\My Dell\uaclauncher.exe"] "C:\Windows\SysNative\tasks\PCDoctorBackgroundMonitorTask-Retry" ["C:\Program Files\My Dell\uaclauncher.exe"] "C:\Windows\SysNative\tasks\SystemToolsDailyTest" ["uaclauncher.exe"] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{A4227721-7268-4CF3-8773-E8099E2CE411}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\WebReg HP Deskjet F2200 series" [C:\Program Files (x86)\HP\Digital Imaging\bin\hpqwrg.exe] "C:\Windows\SysNative\tasks\Apple\AppleSoftwareUpdate" [C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe] "C:\Windows\SysNative\tasks\NCH Software\debutDowngrade" [C:\Program Files (x86)\NCH Software\Debut\debut.exe] "C:\Windows\SysNative\tasks\NCH Software\debutShakeIcon" [C:\Program Files (x86)\NCH Software\Debut\Debut.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}"="C:\Program Files\IB Updater\Firefox" [] [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "{23fcfd51-4958-4f00-80a3-ae97e717ed8b}"="C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5" [31/03/2012 16:38] ==== Firefox Extensions ====================== ExtDir: C:\Users\marre\AppData\Roaming\Mozilla\Firefox\Profiles\extensions - GoPhotoIt - %ExtDir%\gophoto@gophoto.it.xpi ==== Firefox Plugins ====================== ==== Deleted Firefox Extensions ====================== C:\Users\marre\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\gophoto@gophoto.it.xpi deleted ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions ccbgjfdieajmokelnlapbedknchgenne - C:\Users\marre\AppData\Local\CRE\ccbgjfdieajmokelnlapbedknchgenne.crx[] fdloijijlkoblmigdofommgnheckmaki - C:\Program Files (x86)\Funmoods\funmoods\1.5.19.3\funmoodsOEM.crx[] jifflliplgeajjdhmkcfnngfpgbjonjg - C:\Program Files (x86)\Perion\NewTab\newTab.crx[] knkakpihealnpggeceajhaonlmgdkaip - No path found[] nneajnkjbffgblleaoojgaacokifdkhm - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx[12/12/2011 14:13] pfmopbbadnfoelckkcmjjeaaegjpjjbk - C:\Program Files (x86)\Gophoto.it\gophotoit14.crx[] pmlghpafmmnmmkjdhacccolfgnkiboco - C:\Program Files (x86)\1ClickDownload\oneclickdownloader11.crx[] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions ccbgjfdieajmokelnlapbedknchgenne - C:\Users\marre\AppData\Local\CRE\ccbgjfdieajmokelnlapbedknchgenne.crx[] YouTube - marre\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Game Master 2.1 - marre\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccbgjfdieajmokelnlapbedknchgenne Google Search - marre\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Battlefield Play4Free - marre\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkejhbcdagodjdndmfnhaibnealjonei New Tab - marre\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnpmlnedpdikbgdghljdepnljfpkhccn Funmoods - marre\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki ChatZum.com - Easy Pictures zoom - marre\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbpcjmidkkgldeplajgnbpjkfpmpeepb DivX Plus Web Player HTML5 \u003Cvideo\u003E - marre\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm GoPhoto.it - marre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk Gmail - marre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia Game Master 2.1 - marre\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ccbgjfdieajmokelnlapbedknchgenne Web Assistant - marre\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Grepolis Report Converter - marre\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eediamimojgbnjfaalcnlonenfdcogop Pixlr Editor - marre\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icmaknaampgiegkcjlimdiidlhopknpk New tab for Chrome\u2122 - marre\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg Google Wallet - marre\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda DivX Plus Web Player HTML5 \u003Cvideo\u003E - marre\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nneajnkjbffgblleaoojgaacokifdkhm GoPhoto.it - marre\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk ==== Chromium Startpages ====================== C:\Users\marre\AppData\Local\Google\Chrome\User Data\Default\Preferences "homepage": "http://feed.helperbar.com/?publisher=OC&dpid=OC&co=BE&userid=8fe358d3-0ffc-4df2-bc76-63e071440597&affid=111583&searchtype=hp&babsrc=lnkry", "urls_to_restore_on_startup": [ "http://feed.helperbar.com/?publisher=OC&dpid=OC&co=BE&userid=8fe358d3-0ffc-4df2-bc76-63e071440597&affid=111583&searchtype=hp&babsrc=lnkry" ] ==== Chromium Fix ====================== C:\Users\marre\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccbgjfdieajmokelnlapbedknchgenne deleted successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ccbgjfdieajmokelnlapbedknchgenne deleted successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ccbgjfdieajmokelnlapbedknchgenne_0.localstorage deleted successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_ccbgjfdieajmokelnlapbedknchgenne_0.localstorage deleted successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki deleted successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fdloijijlkoblmigdofommgnheckmaki_0.localstorage deleted successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg deleted successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk deleted successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk deleted successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pfmopbbadnfoelckkcmjjeaaegjpjjbk_0.localstorage deleted successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_pfmopbbadnfoelckkcmjjeaaegjpjjbk_0.localstorage deleted successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnpmlnedpdikbgdghljdepnljfpkhccn deleted successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dnpmlnedpdikbgdghljdepnljfpkhccn_0.localstorage deleted successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_dnpmlnedpdikbgdghljdepnljfpkhccn_0 deleted successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd deleted successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Profile 1\Local Storage\chrome-extension_dlnembnfbcpjnepmfjmngjenhhajpdfd_0.localstorage deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.be/" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://search.chatzum.com/" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Start Page"="http://search.chatzum.com/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.google.be/" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&FORM=DLCDF7&pc=MDDC&src=IE-SearchBox" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADFA_nlBE462" {DCDBBF03-BC10-457D-911F-EFB0321D22BE} Search The Web (Softonic) Url="${SRCH_SCP_URL}" ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052} deleted successfully ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ccbgjfdieajmokelnlapbedknchgenne deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\knkakpihealnpggeceajhaonlmgdkaip deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pfmopbbadnfoelckkcmjjeaaegjpjjbk deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pmlghpafmmnmmkjdhacccolfgnkiboco deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\ccbgjfdieajmokelnlapbedknchgenne deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5.5ServiceManager deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recordpad deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RMAlert deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSDMonitor deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\marre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Cache found ==== Empty Chrome Cache ====================== C:\Users\marre\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\marre\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Gast\AppData\Local\Temp emptied successfully C:\Users\marre\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\marre\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\marre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found ==== EOF on zo 09/11/2014 at 17:13:44,83 ======================