Zoek.exe v5.0.0.0 Updated 02-April-2015 Tool run by leopold on zo 05/04/2015 at 21:03:59.01. Microsoft Windows 8.1 Pro 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\leopold\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== Older Logs ====================== C:\zoek-results2015-03-24-193600.log 32402 bytes ==== Empty Folders Check ====================== C:\PROGRA~3\Mozilla deleted successfully C:\Users\leopold\AppData\Local\CarbonPoker deleted successfully C:\Users\leopold\AppData\Local\Comodo deleted successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\PeerDistPub deleted successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\PeerDistRepub deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== "C:\Windows\zoek-delete.exe" not found C:\zoek_backup deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\Windows\SysNative\config\systemprofile\Searches deleted C:\Users\leopold\AppData\Roaming\Mozilla\Firefox\Profiles\d0f4asr1.default-1412631958035\extensions\firefox@ghostery.com.xpi deleted C:\Users\leopold\AppData\Roaming\Mozilla\Firefox\Profiles\d0f4asr1.default-1412631958035\jetpack deleted "C:\windows\SysNative\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat" deleted ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== 2015-03-11 14:30:53 C10A66189DC8C090E7C84873EDCEBC88 2501368 ----a-w- C:\Windows\explorer.exe ====== C:\Users\leopold\AppData\Local\Temp ==== 2015-04-05 12:27:36 E0DC8C6BBC787B972A9A468648DBFD85 1008128 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\libiconv2.dll 2015-04-05 12:27:36 D202BAA425176287017FFE1FB5D1B77C 103424 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\libintl3.dll 2015-04-05 12:27:36 57CAC848FA14AE38F14F9441F8933282 140288 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\pcre3.dll 2015-04-05 12:27:36 547C43567AB8C08EB30F6C6BACB479A3 79360 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\regex2.dll ====== Java Cache ===== ====== C:\Windows\SysWOW64 ===== 2015-03-27 14:02:40 46DE9C72EE0F23B9AB6A625214C16FE3 1124352 ----a-w- C:\Windows\SysWOW64\msctf.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2015-03-29 08:14:07 070C7E37DA667E8DDD06A8D33CC750F9 480368 ----a-w- C:\Windows\Sysnative\FNTCACHE.DAT 2015-03-27 14:02:41 DD301FDB003F9B48EB7628A48BF32D23 677888 ----a-w- C:\Windows\Sysnative\generaltel.dll 2015-03-27 14:02:41 BB86098B80BC4911B52F4C6095E82381 760320 ----a-w- C:\Windows\Sysnative\invagent.dll 2015-03-27 14:02:41 B770418F0FE64D3E986505A6285E91E9 943104 ----a-w- C:\Windows\Sysnative\appraiser.dll 2015-03-27 14:02:41 A871B38A544058768F082598412278DB 30720 ----a-w- C:\Windows\Sysnative\acmigration.dll 2015-03-27 14:02:41 7F19365C2D9CD0AA5E517A96A22AE7C8 1107456 ----a-w- C:\Windows\Sysnative\aeinv.dll 2015-03-27 14:02:41 4E791CFE387374E8651493557B7F9993 227328 ----a-w- C:\Windows\Sysnative\aepdu.dll 2015-03-27 14:02:41 4BAF6A3B8DFDDCE080275B236F4B64BC 414208 ----a-w- C:\Windows\Sysnative\devinv.dll 2015-03-27 14:02:40 3E9BB985DF2FF26CCE840DE1D24E9381 1385256 ----a-w- C:\Windows\Sysnative\msctf.dll ====== C:\Windows\Sysnative\drivers ===== 2015-03-11 14:34:15 D296D0F0DB2CD1504F90405603664493 264000 ----a-w- C:\Windows\Sysnative\drivers\WdFilter.sys 2015-03-11 14:34:15 9F4DF0043965808973023A9B51A11136 114496 ----a-w- C:\Windows\Sysnative\drivers\WdNisDrv.sys 2015-03-11 14:34:15 1751F6B031ADAC34724511057D2E455D 44024 ----a-w- C:\Windows\Sysnative\drivers\WdBoot.sys 2015-03-11 14:33:14 6D3A2565E01B3E4B0F1BEDB0D4B00B3F 1113920 ----a-w- C:\Windows\Sysnative\drivers\ndis.sys 2015-03-11 14:32:53 DC66AE45816614D2999DCD3834DCCC4E 167424 -c--a-w- C:\Windows\Sysnative\drivers\rfcomm.sys 2015-03-11 14:32:53 42F88B57CAE42FC10059C887B3FCFCEA 97792 -c--a-w- C:\Windows\Sysnative\drivers\hidbth.sys ====== C:\Windows\Tasks ====== ====== C:\Windows\Temp ====== ======= C:\Program Files ===== ======= C:\PROGRA~2 ===== 2015-04-05 17:16:06 -------- d-----w- C:\PROGRA~2\COMMON~1\System 2015-03-15 08:23:56 -------- d-----w- C:\PROGRA~2\COMMON~1\Java ======= C: ===== ====== C:\Users\leopold\AppData\Roaming ====== 2015-04-04 12:43:14 3C8D8C90A0DB83CA82747BA67C4C3CF8 1012176 ----a-w- C:\Windows\serviceprofiles\Localservice\AppData\Local\FontCache3.0.0.0.dat 2015-03-25 08:32:05 -------- d-----w- C:\Users\leopold\AppData\Local\CrashDumps 2015-03-24 19:34:57 -------- d-----w- C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp 2015-03-24 19:34:56 -------- d-----w- C:\Users\leopold\AppData\Local\Temp 2015-03-24 19:34:56 -------- d-----w- C:\Users\Default\AppData\Local\Temp 2015-03-24 19:34:56 -------- d-----w- C:\Users\Default User\AppData\Local\Temp ====== C:\Users\leopold ====== 2015-04-05 15:11:40 -------- d-----w- C:\Windows\serviceprofiles\Localservice\winhttp 2015-04-05 15:09:53 E55D0D5D5A3A585BFF48B990708007A5 2208768 ----a-w- C:\Users\leopold\Desktop\adwcleaner_4.200.exe 2015-04-05 14:05:05 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\leopold\Desktop\RSITx64.exe 2015-03-15 08:23:57 -------- d-----w- C:\ProgramData\Sun ====== C: exe-files == 2015-04-05 15:09:53 E55D0D5D5A3A585BFF48B990708007A5 2208768 ----a-w- C:\Users\leopold\Desktop\adwcleaner_4.200.exe 2015-04-05 14:05:05 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\leopold\Desktop\RSITx64.exe 2015-04-01 07:48:32 DD370F1BC3A887A0D7193E4A834B1DF5 443776 ----a-w- C:\Users\leopold\AppData\Local\NVIDIA\NvBackend\Packages\000072d3\CoProc update.19449754.exe 2015-04-01 07:48:32 2E036D90308CA91B86291AE7A8D53FB8 5319392 ----a-w- C:\Users\leopold\AppData\Local\NVIDIA\NvBackend\Packages\000072d7\DAO.19449842.exe 2015-03-31 11:39:04 263F67F1A143E987F73C931D55F1120A 675256 ----a-w- C:\Users\leopold\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe 2015-03-31 11:39:02 B1A9FA60382EA954C4637F1F3DAB8ADD 172984 ----a-w- C:\Users\leopold\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\OAWrapper.exe === C: other files == 2015-04-05 12:27:35 F56A319979F631C141F5FF02DF87FDB1 43563 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\prelim.bat 2015-04-05 12:27:35 DD1E4D974B1672ABD09EFFB225791C4A 1230 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\TDL4.bat 2015-04-05 12:27:35 AD2F52DC72B10AF331692E4A4DD80DFC 18670 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\medfos.bat 2015-04-05 12:27:35 AA0C656F898523BEDF2DA6923197BB80 1264 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\surfvox.bat 2015-04-05 12:27:35 93A6196509429319C854A941F14F1E7C 252 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\ev_clear.bat 2015-04-05 12:27:35 8E6020C14F982CF11B3FE7DBB0CB8EDE 24738 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\searchlnk.bat 2015-04-05 12:27:35 86707BCE5CBB65D9B1C41E249B4423BA 152733 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\firefox.bat 2015-04-05 12:27:35 38A0BDF322ACCC968B0A824C38D50157 29635 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\ask.bat 2015-04-05 12:27:35 37C2F921DAA9AF1149B16747C968B257 11535 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\runvalues.bat 2015-04-05 12:27:35 335DFF8F23E5EC02B5426362F0F8509B 31401 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\iexplore.bat 2015-04-05 12:27:35 2C52A5D8E66B3658260B2E9966C7ED76 194373 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\misc.bat 2015-04-05 12:27:35 26DF73E2D5CBE7C7319D0C8A16FBEDFE 14924 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\get.bat 2015-04-05 12:27:35 0C4649A62845AB5D5DBCC4998477FF6D 1813 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\delfolders.bat 2015-04-05 12:27:35 080CFDE64F31E7B50EECF4552033E84D 9937 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\mws.bat 2015-04-05 12:27:35 048407135C9B1FB6A355E256BD96160D 14192 ----a-w- C:\Users\leopold\AppData\Local\Temp\jrt\chrome.bat 2015-04-02 08:46:00 C29ABF09284D7814656E7C6ABB933A44 301807 ----a-w- C:\Users\leopold\AppData\Roaming\Fenrir Inc\Sleipnir5\~temp\chrome\extension\amazon_1ba.crx ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-21-4093346977-3998776294-3076164987-1001\Software\Microsoft\Windows\CurrentVersion\Run] "f.lux"="C:\Users\leopold\AppData\Local\FluxSoftware\Flux\flux.exe /noshow" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" "OfficeSyncProcess"="C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE" "Gadwin PrintScreen (64-bit)"="C:\Program Files\Gadwin\Gadwin PrintScreen\PrintScreen64.exe /nosplash" "GUDelayStartup"="C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe -delayrun" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe 60" "vmware-tray.exe"="C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe" "cmsc"="c:\program files (x86)\cmcm\Clean Master\cmtray.exe -autorun" "VirtualCloneDrive"="C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe /s" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "f.lux"="C:\Users\leopold\AppData\Local\FluxSoftware\Flux\flux.exe /noshow" "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun" "OfficeSyncProcess"="C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE" "Gadwin PrintScreen (64-bit)"="C:\Program Files\Gadwin\Gadwin PrintScreen\PrintScreen64.exe /nosplash" "GUDelayStartup"="C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe -delayrun" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] "BootRacer"="C:\Program Files (x86)\BootRacer\Bootrace.exe /2" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\Windows\\SysWOW64\\nvinit.dll" ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe /hide /waitservice" "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s" "RtHDVBg_Dolby"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 " "BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe /DelayServices" "NvBackend"="C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" "ShadowPlay"="C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] "BootRacer"="C:\Program Files (x86)\BootRacer\Bootrace.exe /2" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\Windows\\system32\\nvinitx.dll" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\GUDelayStartup] "item"="GUDelayStartup" "command"="\"C:\\Program Files (x86)\\Glary Utilities 5\\StartupManager.exe\" -delayrun" "hkey"="HKLM" "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" ==== Startup Folders ====================== 2014-08-13 10:02:57 564 ----a-w- C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RUN.CMD 2014-08-13 10:02:57 564 ----a-w- C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RUN.CMD ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a-------- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [13/03/2015 11:59] C:\Windows\tasks\GlaryInitialize 5.job --a-------- C:\Program Files (x86)\Glary Utilities 5\Initialize.exe [02/03/2015 07:38] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Acrobat Update Task" [C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe] "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\CCleanerSkipUAC" ["C:\Program Files\CCleaner\CCleaner.exe"] "C:\Windows\SysNative\tasks\GlaryInitialize 5" [C:\Program Files (x86)\Glary Utilities 5\Initialize.exe] "C:\Windows\SysNative\tasks\GU5SkipUAC" [C:\Program Files (x86)\Glary Utilities 5\Integrator.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{209D1D33-301D-4FA2-AF03-4996FEA90EEC}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask" [%systemroot%\system32\sc.exe start osppsvc] ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\leopold\AppData\Roaming\Mozilla\Firefox\Profiles\d0f4asr1.default-1412631958035 user_pref("browser.startup.homepage", "www.google.be"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "belgiumeid@eid.belgium.be"="C:\Program Files\Mozilla Firefox\extensions\belgiumeid@eid.belgium.be" [] ==== Firefox Extensions ====================== ProfilePath: C:\Users\leopold\AppData\Roaming\Mozilla\Firefox\Profiles\d0f4asr1.default-1412631958035 - Belgium eID - %ProfilePath%\extensions\belgiumeid@eid.belgium.be.xpi - ZenMate Security amp; Privacy VPN - %ProfilePath%\extensions\firefox@zenmate.com.xpi - Google Translator - %ProfilePath%\extensions\jid1-dgnIBwQga0SIBw@jetpack.xpi - Clip to OneNote - %ProfilePath%\extensions\{966762eb-7132-4081-ac70-20d20161ad96}.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Belgium eID - %AppDir%\extensions\belgiumeid@eid.belgium.be - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\leopold\AppData\Roaming\Mozilla\Firefox\Profiles\d0f4asr1.default-1412631958035 0CA4180B21C6B728578F3B0433BB740E - G:\VLC\npvlc.dll - VLC Web Plugin FD3DD0EE2D03B2BA55A8FAEC211C3B89 - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director 43583AB4DFD406F4C188342F41B1F91C - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll - Shockwave Flash D2B5242013356AF422A42B9FAA4056C2 - C:\Users\leopold\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.2\npVascoCardReaderPlugin.dll - VASCO Card Reader Plugin FD63DE29FE0A7E738BD81CA0EDDD8020 - C:\Users\leopold\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.2\npVascoCardReaderPlugin64.dll - VASCO Card Reader Plugin ==== Chromium Startpages ====================== C:\Users\leopold\AppData\Local\360Browser\Browser\User Data\Default\Preferences "homepage": "http://360safe.com", ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.be/" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\leopold\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\leopold\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\leopold\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\leopold\AppData\Local\Microsoft\Windows\INetCache\IE\AXW8V28Q will be deleted at reboot C:\Users\leopold\AppData\Local\Microsoft\Windows\INetCache\IE\B6BHTNCN will be deleted at reboot C:\Users\leopold\AppData\Local\Microsoft\Windows\INetCache\IE\N50XJTAO will be deleted at reboot C:\Users\leopold\AppData\Local\Microsoft\Windows\INetCache\IE\PRC0G65D will be deleted at reboot ==== Empty FireFox Cache ====================== C:\Users\leopold\AppData\Local\Mozilla\Firefox\Profiles\d0f4asr1.default-1412631958035\cache2 emptied successfully ==== Empty Chrome Cache ====================== No Chrome Cache found ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files= ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\leopold\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\leopold\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\leopold\AppData\Local\Microsoft\Windows\INetCache\IE\AXW8V28Q" not found "C:\Users\leopold\AppData\Local\Microsoft\Windows\INetCache\IE\B6BHTNCN" not found "C:\Users\leopold\AppData\Local\Microsoft\Windows\INetCache\IE\N50XJTAO" not found "C:\Users\leopold\AppData\Local\Microsoft\Windows\INetCache\IE\PRC0G65D" not found "C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted ==== EOF on zo 05/04/2015 at 21:32:51.87 ======================