Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
I keep getting annoying pop-ups so it's impossible to use the internet.
Message
<blockquote data-quote="Mikeiej" data-source="post: 301385" data-attributes="member: 26304"><p>Zoek.exe v5.0.0.0 Updated 16-November-2014</p><p>Tool run by louise on di 18-11-2014 at 13:47:25,31.</p><p>Microsoft Windows 8.1 6.3.9600 x64</p><p>Running in: Normal Mode Internet Access Detected</p><p>Launched: C:\Users\louise\Downloads\zoek (1).exe [Scan all users] [Script inserted] </p><p></p><p>==== Older Logs ======================</p><p></p><p>C:\zoek-results2014-11-18-124328.log 469 bytes</p><p></p><p>==== System Restore Info ======================</p><p></p><p>18-11-2014 13:49:40 Zoek.exe System Restore Point Created Succesfully.</p><p></p><p>==== Deleting CLSID Registry Keys ======================</p><p></p><p>HKEY_USERS\S-1-5-21-542275556-3985778205-188204485-1001\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully</p><p>HKEY_USERS\S-1-5-21-542275556-3985778205-188204485-1001\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully</p><p>HKEY_USERS\S-1-5-21-542275556-3985778205-188204485-1001\Software\Microsoft\Internet Explorer\SearchScopes\{5E347471-4609-4D3A-9EB2-46E4E8B0AABD} deleted successfully</p><p>HKEY_USERS\S-1-5-21-542275556-3985778205-188204485-1001\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} deleted successfully</p><p>HKEY_USERS\S-1-5-21-542275556-3985778205-188204485-1001\Software\Microsoft\Internet Explorer\SearchScopes\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} deleted successfully</p><p></p><p>==== Deleting CLSID Registry Values ======================</p><p></p><p></p><p>==== Deleting Services ======================</p><p></p><p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util BrowseStudio deleted successfully</p><p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util BrowseStudio deleted successfully</p><p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update BrowseStudio deleted successfully</p><p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update BrowseStudio deleted successfully</p><p></p><p>==== FireFox Fix ======================</p><p></p><p>ProfilePath: C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\6288fqoo.default</p><p></p><p>user.js not found</p><p>---- FireFox user.js and prefs.js backups ---- </p><p></p><p>prefs_18-11-2014_1440_.backup</p><p></p><p>ProfilePath: C:\Users\louise\AppData\Roaming\Mozilla\Firefox\Profiles\fyn8wgqc.default</p><p></p><p>user.js not found</p><p>---- Lines conduit removed from prefs.js ----</p><p>user_pref("browser.newtab.url", "<a href="http://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=2&UP=SPC198540C-" target="_blank">http://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=2&UP=SPC198540C-</a></p><p>---- Lines WebSearch removed from prefs.js ----</p><p>user_pref("browser.search.defaultenginename,S", "WebSearch");</p><p>user_pref("browser.search.defaulturl", "<a href="http://websearch.amaizingsearches.info/?pid=356&r=2014/04/22&hid=11015164002174392595&lg=EN&cc=NL&unqvl=51&l=1" target="_blank">http://websearch.amaizingsearches.info/?pid=356&r=2014/04/22&hid=11015164002174392595&lg=EN&cc=NL&unqvl=51&l=1</a></p><p>user_pref("browser.search.order.1", "WebSearch");</p><p>user_pref("browser.search.order.1,S", "WebSearch");</p><p>user_pref("browser.search.selectedEngine,S", "WebSearch");</p><p>user_pref("browser.startup.homepage", "<a href="http://websearch.amaizingsearches.info/?pid=356&r=2014/04/22&hid=11015164002174392595&lg=EN&cc=NL&unqvl=51" target="_blank">http://websearch.amaizingsearches.info/?pid=356&r=2014/04/22&hid=11015164002174392595&lg=EN&cc=NL&unqvl=51</a>");</p><p>---- FireFox user.js and prefs.js backups ---- </p><p></p><p>prefs_18-11-2014_1440_.backup</p><p></p><p>ProfilePath: C:\Users\louise\AppData\Roaming\Songbird2\Profiles\asr13ccb.default</p><p></p><p>user.js not found</p><p>---- FireFox user.js and prefs.js backups ---- </p><p></p><p>prefs_18-11-2014_1440_.backup</p><p></p><p>==== Batch Command(s) Run By Tool======================</p><p></p><p></p><p>==== Deleting Files \ Folders ======================</p><p></p><p>C:\ProgramData\GreatSave4U deleted</p><p>C:\PROGRA~2\YoutubeAdblocker deleted</p><p>C:\ProgramData\YoutubeAdblocker deleted</p><p>C:\PROGRA~2\safEwebb deleted</p><p>C:\ProgramData\safEwebb deleted</p><p>C:\PROGRA~2\SNT deleted</p><p>C:\ProgramData\SNT deleted</p><p>C:\PROGRA~2\GoSave deleted</p><p>C:\PROGRA~3\ggpkdamlmloooacfmbkagcddacafnkdo deleted</p><p>C:\PROGRA~3\ijfdappinnocgmclafolamccdibpdnjo deleted</p><p>C:\PROGRA~3\1861120512064557018 deleted</p><p>C:\PROGRA~3\19d4073ebdcd0fda deleted</p><p>C:\PROGRA~3\Rightapp software deleted</p><p>C:\PROGRA~2\DeltaFix deleted</p><p>C:\PROGRA~2\SearchProtect deleted</p><p>C:\PROGRA~2\WSE_Astromenda deleted</p><p>C:\PROGRA~2\WSE_Vosteran deleted</p><p>C:\rct2.exe deleted</p><p>C:\found.000 deleted</p><p>C:\found.001 deleted</p><p>C:\Users\Gast\AppData\Roaming\Systweak deleted</p><p>C:\Users\louise\AppData\Roaming\WB.CFG deleted</p><p>C:\Users\louise\AppData\Roaming\WSE_Astromenda deleted</p><p>C:\Users\louise\AppData\Roaming\WSE_Vosteran deleted</p><p>C:\Users\louise\AppData\Roaming\PC Speed Maximizer deleted</p><p>C:\Users\louise\AppData\Roaming\Astromenda deleted</p><p>C:\Users\louise\AppData\Roaming\Systweak deleted</p><p>C:\PROGRA~3\eBay deleted</p><p>C:\PROGRA~3\InstallMate deleted</p><p>C:\PROGRA~3\Package Cache deleted</p><p>C:\Users\Gast\AppData\Local\SearchProtect deleted</p><p>C:\Users\louise\AppData\Local\SearchProtect deleted</p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Maximizer deleted</p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted</p><p>C:\WINDOWS\SysNative\roboot64.exe deleted</p><p>C:\windows\SysNative\tasks\PC Speed Maximizer Schedule deleted</p><p>C:\WINDOWS\tasks\GS_Booster-S-576482620.job deleted</p><p>C:\windows\SysNative\tasks\GS_Booster-S-576482620 deleted</p><p>C:\windows\SysNative\tasks\WSE_Astromenda deleted</p><p>C:\windows\SysNative\tasks\WSE_Vosteran deleted</p><p>C:\WINDOWS\tasks\WSE_Astromenda.job deleted</p><p>C:\WINDOWS\tasks\WSE_Vosteran.job deleted</p><p>C:\windows\SysNative\drivers\{e8294a7e-8442-4f3a-8722-cb5c3f67ed67}Gw64.sys deleted</p><p>C:\windows\SysNative\drivers\{fd74c1d1-1ac3-43f9-8336-32679dc7de45}Gw64.sys deleted</p><p>C:\windows\SysNative\GroupPolicy\machine deleted</p><p>C:\windows\SysNative\GroupPolicy\gpt.ini deleted</p><p>C:\WINDOWS\Syswow64\SearchProtect deleted</p><p>C:\Users\louise\Documents\PC Speed Maximizer deleted</p><p>C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\6288fqoo.default\extensions\staged deleted</p><p>C:\Users\louise\AppData\Roaming\Mozilla\Firefox\Profiles\fyn8wgqc.default\searchplugins\conduit-search.xml deleted</p><p>C:\Users\louise\AppData\Roaming\Mozilla\Firefox\Profiles\fyn8wgqc.default\searchplugins\WebSearch.xml deleted</p><p>C:\Users\louise\AppData\Roaming\Mozilla\Firefox\Profiles\fyn8wgqc.default\extensions\staged deleted</p><p>C:\Users\louise\Desktop\Continue Installation.lnk deleted</p><p>C:\Users\louise\Desktop\PC Speed Maximizer.lnk deleted</p><p>"C:\PROGRA~2\PC Speed Maximizer\SPMSchedule.exe" deleted</p><p>"C:\Users\louise\AppData\Roaming\Search Protection\SearchProtection.exe" deleted</p><p>"C:\PROGRA~2\BrowseStudio\updateBrowseStudio.exe" deleted</p><p>"C:\PROGRA~3\Trusted Publisher\GS_Booster\GS_Booster.exe" deleted</p><p>"C:\PROGRA~2\BrowseStudio\bin\BrowseStudio.BOAS.exe.tmp" deleted</p><p>"C:\PROGRA~2\BrowseStudio\bin\BrowseStudio.BOAS.zip" deleted</p><p>"C:\PROGRA~2\BrowseStudio\bin\BrowseStudio.BOASHelper.exe" deleted</p><p>"C:\PROGRA~2\BrowseStudio\bin\BrowseStudio.BrowserAdapter.exe" deleted</p><p>"C:\PROGRA~2\BrowseStudio\bin\BrowseStudio.BrowserAdapter64.exe" not deleted</p><p>"C:\PROGRA~2\BrowseStudio\bin\BrowseStudio.PurBrowse64.exe" deleted</p><p>"C:\PROGRA~2\BrowseStudio\bin\sqlite3.dll" deleted</p><p>"C:\PROGRA~2\BrowseStudio\bin\utilBrowseStudio.exe" deleted</p><p>"C:\PROGRA~2\BrowseStudio\bin\{e8294a7e-8442-4f3a-8722-cb5c3f67ed67}.dll" deleted</p><p>"C:\PROGRA~2\BrowseStudio\bin\{e8294a7e-8442-4f3a-8722-cb5c3f67ed67}64.dll" deleted</p><p>"C:\PROGRA~2\PC Speed Maximizer" deleted</p><p>"C:\Users\louise\AppData\Roaming\Search Protection" deleted</p><p>"C:\PROGRA~3\Trusted Publisher" not deleted</p><p>"C:\PROGRA~2\BrowseStudio" not deleted</p><p>"C:\PROGRA~3\Trusted Publisher\GS_Booster" not deleted</p><p>"C:\PROGRA~2\BrowseStudio\bin" not deleted</p><p></p><p>==== Firefox Extensions ======================</p><p></p><p>ProfilePath: C:\Users\louise\AppData\Roaming\Songbird2\Profiles\asr13ccb.default</p><p>- Undetermined - C:\Program Files (x86)\Songbird\extensions\<a href="mailto:albumart@songbirdnest.com">albumart@songbirdnest.com</a></p><p>- Undetermined - C:\Program Files (x86)\Songbird\extensions\<a href="mailto:gonzo@songbirdnest.com">gonzo@songbirdnest.com</a></p><p>- Undetermined - C:\Program Files (x86)\Songbird\extensions\<a href="mailto:philips-addon-manager@songbirdnest.com">philips-addon-manager@songbirdnest.com</a></p><p>- Undetermined - C:\Program Files (x86)\Songbird\extensions\<a href="mailto:pinkmartini@songbirdnest.com">pinkmartini@songbirdnest.com</a></p><p>- Undetermined - C:\Program Files (x86)\Songbird\extensions\<a href="mailto:purplerain@songbirdnest.com">purplerain@songbirdnest.com</a></p><p>- Undetermined - C:\Program Files (x86)\Songbird\extensions\<a href="mailto:sharing@songbirdnest.com">sharing@songbirdnest.com</a></p><p>- Undetermined - C:\Program Files (x86)\Songbird\extensions\<a href="mailto:soundboard@songbirdnest.com">soundboard@songbirdnest.com</a></p><p></p><p>==== Firefox Plugins ======================</p><p></p><p>Profilepath: C:\Users\louise\AppData\Roaming\Mozilla\Firefox\Profiles\fyn8wgqc.default</p><p>E5AF72B7353FF8D431A7C463A4229524 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll - Shockwave Flash</p><p>2616B4D6D04F18C579B7861F02B0B592 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.130.20</p><p>369EC92E676537A3F86C5074BA30FC96 - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System</p><p></p><p></p><p>==== Fake Chromium Profiles Check ======================</p><p></p><p>Fake profile C:\Users\Administrator\AppData\Local\Torch deleted</p><p>Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome deleted</p><p>Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome SxS deleted</p><p>Fake profile C:\Users\Administrator\AppData\Local\Comodo\Dragon deleted</p><p>Fake profile C:\Users\Gast\AppData\Local\Torch deleted</p><p>Fake profile C:\Users\Gast\AppData\Local\Google\Chrome SxS deleted</p><p>Fake profile C:\Users\Gast\AppData\Local\Comodo\Dragon deleted</p><p>Fake profile C:\Users\HomeGroupUser$\AppData\Local\Torch deleted</p><p>Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome deleted</p><p>Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS deleted</p><p>Fake profile C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon deleted</p><p>Fake profile C:\Users\louise\AppData\Local\Torch deleted</p><p>Fake profile C:\Users\louise\AppData\Local\Google\Chrome SxS deleted</p><p>Fake profile C:\Users\louise\AppData\Local\Comodo\Dragon deleted</p><p></p><p>==== Chromium Look ======================</p><p></p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions</p><p>oilkkkefbalmbfppgjmgjoefbclebkce - No path found[]</p><p>pfkfdlcdbajamklbneflfbcmfgddmpae - No path found[]</p><p></p><p>HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions</p><p>oilkkkefbalmbfppgjmgjoefbclebkce - No path found[]</p><p>pfkfdlcdbajamklbneflfbcmfgddmpae - No path found[]</p><p></p><p>avast Online Security - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki</p><p>Facebook Invite Them All - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\jladghljinmlokelojmdmblikkifabea</p><p>BrowseStudio - louise\AppData\Local\Google\Chrome\User Data\Default\Extensions\fappblnaebeochecpgnolonpeplcpkig</p><p>Facebook Invite Them All - louise\AppData\Local\Google\Chrome\User Data\Default\Extensions\jladghljinmlokelojmdmblikkifabea</p><p></p><p>==== Chromium Startpages ======================</p><p></p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Preferences</p><p>"homepage": "<a href="http://Vosteran.com/?f=1&a=vst_ir_14_46_ch&cd=2XzuyEtN2Y1L1Qzu0B0AyByCtA0F0CtAtDyE0Azy0EyByEtAtN0D0Tzu0StCtDyDtDtN1L2XzutAtFyCtFyEtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAtC0BtBtDtB0ByDtGtDyBtCyBtGtC0C0D0CtGyEzz0EtCtGyDyDyC0F0CtCyC0AyCyEzz0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzzztA0EzzyC0C0EtGyEyB0EtBtGyEzzyEyBtGzz0BtA0AtGtCtB0B0E0AtDtByDtBtDyE0B2Q&cr=917827958&ir=" target="_blank">http://Vosteran.com/?f=1&a=vst_ir_14_46_ch&cd=2XzuyEtN2Y1L1Qzu0B0AyByCtA0F0CtAtDyE0Azy0EyByEtAtN0D0Tzu0StCtDyDtDtN1L2XzutAtFyCtFyEtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAtC0BtBtDtB0ByDtGtDyBtCyBtGtC0C0D0CtGyEzz0EtCtGyDyDyC0F0CtCyC0AyCyEzz0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzzztA0EzzyC0C0EtGyEyB0EtBtGyEzzyEyBtGzz0BtA0AtGtCtB0B0E0AtDtByDtBtDyE0B2Q&cr=917827958&ir=</a>",</p><p>"startup_urls": [ "<a href="http://Vosteran.com/?f=7&a=vst_ir_14_46_ch&cd=2XzuyEtN2Y1L1Qzu0B0AyByCtA0F0CtAtDyE0Azy0EyByEtAtN0D0Tzu0StCtDyDtDtN1L2XzutAtFyCtFyEtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAtC0BtBtDtB0ByDtGtDyBtCyBtGtC0C0D0CtGyEzz0EtCtGyDyDyC0F0CtCyC0AyCyEzz0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzzztA0EzzyC0C0EtGyEyB0EtBtGyEzzyEyBtGzz0BtA0AtGtCtB0B0E0AtDtByDtBtDyE0B2Q&cr=917827958&ir=" target="_blank">http://Vosteran.com/?f=7&a=vst_ir_14_46_ch&cd=2XzuyEtN2Y1L1Qzu0B0AyByCtA0F0CtAtDyE0Azy0EyByEtAtN0D0Tzu0StCtDyDtDtN1L2XzutAtFyCtFyEtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAtC0BtBtDtB0ByDtGtDyBtCyBtGtC0C0D0CtGyEzz0EtCtGyDyDyC0F0CtCyC0AyCyEzz0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzzztA0EzzyC0C0EtGyEyB0EtBtGyEzzyEyBtGzz0BtA0AtGtCtB0B0E0AtDtByDtBtDyE0B2Q&cr=917827958&ir=</a>", "<a href="http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX" target="_blank">http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX</a>" ],</p><p></p><p></p><p>==== Chromium Fix ======================</p><p></p><p>C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_<a href="http://www.superfish.com_0.localstorage" target="_blank">www.superfish.com_0.localstorage</a> deleted successfully</p><p>C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_<a href="http://www.superfish.com_0.localstorage-journal" target="_blank">www.superfish.com_0.localstorage-journal</a> deleted successfully</p><p>C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_<a href="http://www.superfish.com_0.localstorage" target="_blank">www.superfish.com_0.localstorage</a> deleted successfully</p><p>C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_<a href="http://www.superfish.com_0.localstorage-journal" target="_blank">www.superfish.com_0.localstorage-journal</a> deleted successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_<a href="http://www.superfish.com_0.localstorage" target="_blank">www.superfish.com_0.localstorage</a> deleted successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_<a href="http://www.superfish.com_0.localstorage-journal" target="_blank">www.superfish.com_0.localstorage-journal</a> deleted successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_<a href="http://www.superfish.com_0.localstorage" target="_blank">www.superfish.com_0.localstorage</a> deleted successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_<a href="http://www.superfish.com_0.localstorage-journal" target="_blank">www.superfish.com_0.localstorage-journal</a> deleted successfully</p><p>C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.amaizingsearches.info_0.localstorage deleted successfully</p><p>C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.amaizingsearches.info_0.localstorage-journal deleted successfully</p><p>C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage deleted successfully</p><p>C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage-journal deleted successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage deleted successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage-journal deleted successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage deleted successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage-journal deleted successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_<a href="http://www.great-save.com_0.localstorage" target="_blank">www.great-save.com_0.localstorage</a> deleted successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_<a href="http://www.great-save.com_0.localstorage-journal" target="_blank">www.great-save.com_0.localstorage-journal</a> deleted successfully</p><p>C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\jladghljinmlokelojmdmblikkifabea deleted successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Extensions\jladghljinmlokelojmdmblikkifabea deleted successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jladghljinmlokelojmdmblikkifabea_0.localstorage deleted successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jladghljinmlokelojmdmblikkifabea_0.localstorage-journal deleted successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Extensions\fappblnaebeochecpgnolonpeplcpkig deleted successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fappblnaebeochecpgnolonpeplcpkig_0.localstorage deleted successfully</p><p></p><p>==== Set IE to Default ======================</p><p></p><p>Old Values:</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]</p><p>"Start Page"="<a href="http://Vosteran.com/?f=1&a=vst_ir_14_46_ch&cd=2XzuyEtN2Y1L1Qzu0B0AyByCtA0F0CtAtDyE0Azy0EyByEtAtN0D0Tzu0StCtDyDtDtN1L2XzutAtFyCtFyEtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAtC0BtBtDtB0ByDtGtDyBtCyBtGtC0C0D0CtGyEzz0EtCtGyDyDyC0F0CtCyC0AyCyEzz0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzzztA0EzzyC0C0EtGyEyB0EtBtGyEzzyEyBtGzz0BtA0AtGtCtB0B0E0AtDtByDtBtDyE0B2Q&cr=917827958&ir=" target="_blank">http://Vosteran.com/?f=1&a=vst_ir_14_46_ch&cd=2XzuyEtN2Y1L1Qzu0B0AyByCtA0F0CtAtDyE0Azy0EyByEtAtN0D0Tzu0StCtDyDtDtN1L2XzutAtFyCtFyEtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAtC0BtBtDtB0ByDtGtDyBtCyBtGtC0C0D0CtGyEzz0EtCtGyDyDyC0F0CtCyC0AyCyEzz0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzzztA0EzzyC0C0EtGyEyB0EtBtGyEzzyEyBtGzz0BtA0AtGtCtB0B0E0AtDtByDtBtDyE0B2Q&cr=917827958&ir=</a>"</p><p>"Search Page"="<a href="http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}" target="_blank">http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}</a>"</p><p>"Default_Page_URL"="<a href="http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX" target="_blank">http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX</a>"</p><p>"Search Bar"="<a href="http://www.google.com/ie" target="_blank">http://www.google.com/ie</a>"</p><p>"Default_Search_URL"="<a href="http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}" target="_blank">http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]</p><p>"Default_Search_URL"="<a href="http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}" target="_blank">http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}</a>"</p><p>"Default_Page_URL"="<a href="http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX" target="_blank">http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX</a>"</p><p>"Start Page"="<a href="http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX" target="_blank">http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX</a>"</p><p>"Search Page"="<a href="http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}" target="_blank">http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]</p><p>"Default_Search_URL"="<a href="http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}" target="_blank">http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}</a>"</p><p>"Default_Page_URL"="<a href="http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX" target="_blank">http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX</a>"</p><p>"Start Page"="<a href="http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX" target="_blank">http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX</a>"</p><p>"Search Page"="<a href="http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}" target="_blank">http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}</a>"</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]</p><p>@="<a href="http://www.google.com/search?q=%s" target="_blank">http://www.google.com/search?q=%s</a>"</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]</p><p>"SearchAssistant"="<a href="http://www.google.com/ie" target="_blank">http://www.google.com/ie</a>"</p><p>"Default_Search_URL"="<a href="http://www.google.com/ie" target="_blank">http://www.google.com/ie</a>"</p><p>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]</p><p>"DefaultScope"="{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}"</p><p>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}] not found</p><p></p><p>New Values:</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]</p><p>"Search Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>"</p><p>"Search Bar"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>"</p><p>"Default_Search_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>"</p><p>"Default_Page_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>"</p><p>"Start Page"="<a href="http://Vosteran.com/?f=1&a=vst_ir_14_46_ch&cd=2XzuyEtN2Y1L1Qzu0B0AyByCtA0F0CtAtDyE0Azy0EyByEtAtN0D0Tzu0StCtDyDtDtN1L2XzutAtFyCtFyEtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAtC0BtBtDtB0ByDtGtDyBtCyBtGtC0C0D0CtGyEzz0EtCtGyDyDyC0F0CtCyC0AyCyEzz0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzzztA0EzzyC0C0EtGyEyB0EtBtGyEzzyEyBtGzz0BtA0AtGtCtB0B0E0AtDtByDtBtDyE0B2Q&cr=917827958&ir=" target="_blank">http://Vosteran.com/?f=1&a=vst_ir_14_46_ch&cd=2XzuyEtN2Y1L1Qzu0B0AyByCtA0F0CtAtDyE0Azy0EyByEtAtN0D0Tzu0StCtDyDtDtN1L2XzutAtFyCtFyEtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAtC0BtBtDtB0ByDtGtDyBtCyBtGtC0C0D0CtGyEzz0EtCtGyDyDyC0F0CtCyC0AyCyEzz0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzzztA0EzzyC0C0EtGyEyB0EtBtGyEzzyEyBtGzz0BtA0AtGtCtB0B0E0AtDtByDtBtDyE0B2Q&cr=917827958&ir=</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]</p><p>"Default_Search_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>"</p><p>"Search Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>"</p><p>"Default_Page_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>"</p><p>"Start Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]</p><p>"Default_Search_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>"</p><p>"Search Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>"</p><p>"Default_Page_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>"</p><p>"Start Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>"</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]</p><p>"(Default)"="<a href="http://search.msn.com/results.asp?q=%s" target="_blank">http://search.msn.com/results.asp?q=%s</a>"</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]</p><p>"Default_Search_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>"</p><p>"SearchAssistant"="<a href="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" target="_blank">http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm</a>"</p><p>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]</p><p>"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"</p><p></p><p>==== All HKCU SearchScopes ======================</p><p></p><p>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes</p><p>{012E1000-F331-11DB-8314-0800200C9A66} Google Url="<a href="http://www.google.com/search?q={searchTerms}" target="_blank">http://www.google.com/search?q={searchTerms}</a>"</p><p>{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="<a href="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" target="_blank">http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC</a>"</p><p>{2E00D31D-D171-423D-836D-1A4D7EA7F1A9} Vosteran Url="<a href="http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ir_14_46_ch&cd=2XzuyEtN2Y1L1Qzu0B0AyByCtA0F0CtAtDyE0Azy0EyByEtAtN0D0Tzu0StCtDyDtDtN1L2XzutAtFyCtFyEtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAtC0BtBtDtB0ByDtGtDyBtCyBtGtC0C0D0CtGyEzz0EtCtGyDyDyC0F0CtCyC0AyCyEzz0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzzztA0EzzyC0C0EtGyEyB0EtBtGyEzzyEyBtGzz0BtA0AtGtCtB0B0E0AtDtByDtBtDyE0B2Q&cr=917827958&ir=" target="_blank">http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ir_14_46_ch&cd=2XzuyEtN2Y1L1Qzu0B0AyByCtA0F0CtAtDyE0Azy0EyByEtAtN0D0Tzu0StCtDyDtDtN1L2XzutAtFyCtFyEtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAtC0BtBtDtB0ByDtGtDyBtCyBtGtC0C0D0CtGyEzz0EtCtGyDyDyC0F0CtCyC0AyCyEzz0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzzztA0EzzyC0C0EtGyEyB0EtBtGyEzzyEyBtGzz0BtA0AtGtCtB0B0E0AtDtByDtBtDyE0B2Q&cr=917827958&ir=</a>"</p><p>{3C3FEF63-0EC4-4CFA-8281-367BD6EFCB13} Bing Url="<a href="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02" target="_blank">http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02</a>"</p><p>{57E80CD9-B9EB-4E52-88B1-78EFAE135B7A} Google Url="<a href="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8" target="_blank">http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8</a>"</p><p>{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Goo Url="<a href="http://www.google.com/search?q={sear" target="_blank">http://www.google.com/search?q={sear</a>"</p><p>{A5EE07E2-8FF8-49B7-BAA7-AEE84C8D4A3A} eBay Url="<a href="http://rover.ebay.com/rover/1/1346-81661-16445-14/4?mpre=http://shop.ebay.nl/?oemInLn=ieSrch-&_nkw={searchTerms}" target="_blank">http://rover.ebay.com/rover/1/1346-81661-16445-14/4?mpre=http://shop.ebay.nl/?oemInLn=ieSrch-&_nkw={searchTerms}</a>"</p><p></p><p>==== Deleting CLSID Registry Keys ======================</p><p></p><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a4b0faf0-9c89-4a85-a1a7-32410f746f0e} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a4b0faf0-9c89-4a85-a1a7-32410f746f0e} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{a4b0faf0-9c89-4a85-a1a7-32410f746f0e} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{a4b0faf0-9c89-4a85-a1a7-32410f746f0e} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4b0faf0-9c89-4a85-a1a7-32410f746f0e} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4b0faf0-9c89-4a85-a1a7-32410f746f0e} deleted successfully</p><p></p><p>==== Deleting CLSID Registry Values ======================</p><p></p><p></p><p>==== Deleting Registry Keys ======================</p><p></p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\fefc37f1-7a94-4572-95eb-9bff2bdaf278 deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae deleted successfully</p><p>HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce deleted successfully</p><p>HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{45606A90-3363-3A3B-1C15-C40E77F4DAA0} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{497C131E-2032-051B-B32A-C69A960FBB13} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C87834EB-A2A0-B9D4-AA9A-C263D1191051} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\S-576482620 deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{fc67e7a0} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PC Speed Maximizer_is1 deleted successfully</p><p></p><p>==== Empty IE Cache ======================</p><p></p><p>C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Users\Gast\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully</p><p>C:\Users\louise\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully</p><p>C:\Users\louise\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully</p><p>C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully</p><p>C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully</p><p>C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully</p><p>C:\Users\Gast\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully</p><p>C:\Users\louise\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully</p><p>C:\Users\louise\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully</p><p>C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully</p><p>C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully</p><p></p><p>==== Empty FireFox Cache ======================</p><p></p><p>C:\Users\Gast\AppData\Local\Mozilla\Firefox\Profiles\6288fqoo.default\Cache emptied successfully</p><p>C:\Users\louise\AppData\Local\Mozilla\Firefox\Profiles\fyn8wgqc.default\Cache emptied successfully</p><p></p><p>==== Empty Chrome Cache ======================</p><p></p><p>C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully</p><p>C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully</p><p></p><p>==== Empty All Flash Cache ======================</p><p></p><p>Flash Cache Emptied Successfully</p><p></p><p>==== Empty All Java Cache ======================</p><p></p><p>No Java Cache Found</p><p></p><p>==== C:\zoek_backup content ======================</p><p></p><p>C:\zoek_backup (files=327 folders=114 113489095 bytes)</p><p></p><p>==== Empty Temp Folders ======================</p><p></p><p>C:\Users\Administrator\AppData\Local\Temp emptied successfully</p><p>C:\Users\Default\AppData\Local\Temp emptied successfully</p><p>C:\Users\Default User\AppData\Local\Temp emptied successfully</p><p>C:\Users\Gast\AppData\Local\Temp emptied successfully</p><p>C:\Users\louise\AppData\Local\Temp will be emptied at reboot</p><p>C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully</p><p>C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully</p><p>C:\WINDOWS\Temp will be emptied at reboot</p><p></p><p>==== After Reboot ======================</p><p></p><p>==== Empty Temp Folders ======================</p><p></p><p>C:\WINDOWS\Temp successfully emptied</p><p>C:\Users\louise\AppData\Local\Temp successfully emptied</p><p></p><p>==== Empty Recycle Bin ======================</p><p></p><p>C:\$RECYCLE.BIN successfully emptied</p><p></p><p>==== Deleting Files / Folders ======================</p><p></p><p>"C:\PROGRA~2\BrowseStudio\bin\BrowseStudio.BrowserAdapter64.exe" not found</p><p>"C:\PROGRA~3\Trusted Publisher" not found</p><p>"C:\PROGRA~2\BrowseStudio" not found</p><p></p><p>==== EOF on di 18-11-2014 at 15:32:57,00 ======================</p></blockquote><p></p>
[QUOTE="Mikeiej, post: 301385, member: 26304"] Zoek.exe v5.0.0.0 Updated 16-November-2014 Tool run by louise on di 18-11-2014 at 13:47:25,31. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\louise\Downloads\zoek (1).exe [Scan all users] [Script inserted] ==== Older Logs ====================== C:\zoek-results2014-11-18-124328.log 469 bytes ==== System Restore Info ====================== 18-11-2014 13:49:40 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-542275556-3985778205-188204485-1001\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully HKEY_USERS\S-1-5-21-542275556-3985778205-188204485-1001\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} deleted successfully HKEY_USERS\S-1-5-21-542275556-3985778205-188204485-1001\Software\Microsoft\Internet Explorer\SearchScopes\{5E347471-4609-4D3A-9EB2-46E4E8B0AABD} deleted successfully HKEY_USERS\S-1-5-21-542275556-3985778205-188204485-1001\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} deleted successfully HKEY_USERS\S-1-5-21-542275556-3985778205-188204485-1001\Software\Microsoft\Internet Explorer\SearchScopes\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util BrowseStudio deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util BrowseStudio deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update BrowseStudio deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update BrowseStudio deleted successfully ==== FireFox Fix ====================== ProfilePath: C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\6288fqoo.default user.js not found ---- FireFox user.js and prefs.js backups ---- prefs_18-11-2014_1440_.backup ProfilePath: C:\Users\louise\AppData\Roaming\Mozilla\Firefox\Profiles\fyn8wgqc.default user.js not found ---- Lines conduit removed from prefs.js ---- user_pref("browser.newtab.url", "[url]http://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=2&UP=SPC198540C-[/url] ---- Lines WebSearch removed from prefs.js ---- user_pref("browser.search.defaultenginename,S", "WebSearch"); user_pref("browser.search.defaulturl", "[url]http://websearch.amaizingsearches.info/?pid=356&r=2014/04/22&hid=11015164002174392595&lg=EN&cc=NL&unqvl=51&l=1[/url] user_pref("browser.search.order.1", "WebSearch"); user_pref("browser.search.order.1,S", "WebSearch"); user_pref("browser.search.selectedEngine,S", "WebSearch"); user_pref("browser.startup.homepage", "[url]http://websearch.amaizingsearches.info/?pid=356&r=2014/04/22&hid=11015164002174392595&lg=EN&cc=NL&unqvl=51[/url]"); ---- FireFox user.js and prefs.js backups ---- prefs_18-11-2014_1440_.backup ProfilePath: C:\Users\louise\AppData\Roaming\Songbird2\Profiles\asr13ccb.default user.js not found ---- FireFox user.js and prefs.js backups ---- prefs_18-11-2014_1440_.backup ==== Batch Command(s) Run By Tool====================== ==== Deleting Files \ Folders ====================== C:\ProgramData\GreatSave4U deleted C:\PROGRA~2\YoutubeAdblocker deleted C:\ProgramData\YoutubeAdblocker deleted C:\PROGRA~2\safEwebb deleted C:\ProgramData\safEwebb deleted C:\PROGRA~2\SNT deleted C:\ProgramData\SNT deleted C:\PROGRA~2\GoSave deleted C:\PROGRA~3\ggpkdamlmloooacfmbkagcddacafnkdo deleted C:\PROGRA~3\ijfdappinnocgmclafolamccdibpdnjo deleted C:\PROGRA~3\1861120512064557018 deleted C:\PROGRA~3\19d4073ebdcd0fda deleted C:\PROGRA~3\Rightapp software deleted C:\PROGRA~2\DeltaFix deleted C:\PROGRA~2\SearchProtect deleted C:\PROGRA~2\WSE_Astromenda deleted C:\PROGRA~2\WSE_Vosteran deleted C:\rct2.exe deleted C:\found.000 deleted C:\found.001 deleted C:\Users\Gast\AppData\Roaming\Systweak deleted C:\Users\louise\AppData\Roaming\WB.CFG deleted C:\Users\louise\AppData\Roaming\WSE_Astromenda deleted C:\Users\louise\AppData\Roaming\WSE_Vosteran deleted C:\Users\louise\AppData\Roaming\PC Speed Maximizer deleted C:\Users\louise\AppData\Roaming\Astromenda deleted C:\Users\louise\AppData\Roaming\Systweak deleted C:\PROGRA~3\eBay deleted C:\PROGRA~3\InstallMate deleted C:\PROGRA~3\Package Cache deleted C:\Users\Gast\AppData\Local\SearchProtect deleted C:\Users\louise\AppData\Local\SearchProtect deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Maximizer deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\WINDOWS\SysNative\roboot64.exe deleted C:\windows\SysNative\tasks\PC Speed Maximizer Schedule deleted C:\WINDOWS\tasks\GS_Booster-S-576482620.job deleted C:\windows\SysNative\tasks\GS_Booster-S-576482620 deleted C:\windows\SysNative\tasks\WSE_Astromenda deleted C:\windows\SysNative\tasks\WSE_Vosteran deleted C:\WINDOWS\tasks\WSE_Astromenda.job deleted C:\WINDOWS\tasks\WSE_Vosteran.job deleted C:\windows\SysNative\drivers\{e8294a7e-8442-4f3a-8722-cb5c3f67ed67}Gw64.sys deleted C:\windows\SysNative\drivers\{fd74c1d1-1ac3-43f9-8336-32679dc7de45}Gw64.sys deleted C:\windows\SysNative\GroupPolicy\machine deleted C:\windows\SysNative\GroupPolicy\gpt.ini deleted C:\WINDOWS\Syswow64\SearchProtect deleted C:\Users\louise\Documents\PC Speed Maximizer deleted C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\6288fqoo.default\extensions\staged deleted C:\Users\louise\AppData\Roaming\Mozilla\Firefox\Profiles\fyn8wgqc.default\searchplugins\conduit-search.xml deleted C:\Users\louise\AppData\Roaming\Mozilla\Firefox\Profiles\fyn8wgqc.default\searchplugins\WebSearch.xml deleted C:\Users\louise\AppData\Roaming\Mozilla\Firefox\Profiles\fyn8wgqc.default\extensions\staged deleted C:\Users\louise\Desktop\Continue Installation.lnk deleted C:\Users\louise\Desktop\PC Speed Maximizer.lnk deleted "C:\PROGRA~2\PC Speed Maximizer\SPMSchedule.exe" deleted "C:\Users\louise\AppData\Roaming\Search Protection\SearchProtection.exe" deleted "C:\PROGRA~2\BrowseStudio\updateBrowseStudio.exe" deleted "C:\PROGRA~3\Trusted Publisher\GS_Booster\GS_Booster.exe" deleted "C:\PROGRA~2\BrowseStudio\bin\BrowseStudio.BOAS.exe.tmp" deleted "C:\PROGRA~2\BrowseStudio\bin\BrowseStudio.BOAS.zip" deleted "C:\PROGRA~2\BrowseStudio\bin\BrowseStudio.BOASHelper.exe" deleted "C:\PROGRA~2\BrowseStudio\bin\BrowseStudio.BrowserAdapter.exe" deleted "C:\PROGRA~2\BrowseStudio\bin\BrowseStudio.BrowserAdapter64.exe" not deleted "C:\PROGRA~2\BrowseStudio\bin\BrowseStudio.PurBrowse64.exe" deleted "C:\PROGRA~2\BrowseStudio\bin\sqlite3.dll" deleted "C:\PROGRA~2\BrowseStudio\bin\utilBrowseStudio.exe" deleted "C:\PROGRA~2\BrowseStudio\bin\{e8294a7e-8442-4f3a-8722-cb5c3f67ed67}.dll" deleted "C:\PROGRA~2\BrowseStudio\bin\{e8294a7e-8442-4f3a-8722-cb5c3f67ed67}64.dll" deleted "C:\PROGRA~2\PC Speed Maximizer" deleted "C:\Users\louise\AppData\Roaming\Search Protection" deleted "C:\PROGRA~3\Trusted Publisher" not deleted "C:\PROGRA~2\BrowseStudio" not deleted "C:\PROGRA~3\Trusted Publisher\GS_Booster" not deleted "C:\PROGRA~2\BrowseStudio\bin" not deleted ==== Firefox Extensions ====================== ProfilePath: C:\Users\louise\AppData\Roaming\Songbird2\Profiles\asr13ccb.default - Undetermined - C:\Program Files (x86)\Songbird\extensions\[email]albumart@songbirdnest.com[/email] - Undetermined - C:\Program Files (x86)\Songbird\extensions\[email]gonzo@songbirdnest.com[/email] - Undetermined - C:\Program Files (x86)\Songbird\extensions\[email]philips-addon-manager@songbirdnest.com[/email] - Undetermined - C:\Program Files (x86)\Songbird\extensions\[email]pinkmartini@songbirdnest.com[/email] - Undetermined - C:\Program Files (x86)\Songbird\extensions\[email]purplerain@songbirdnest.com[/email] - Undetermined - C:\Program Files (x86)\Songbird\extensions\[email]sharing@songbirdnest.com[/email] - Undetermined - C:\Program Files (x86)\Songbird\extensions\[email]soundboard@songbirdnest.com[/email] ==== Firefox Plugins ====================== Profilepath: C:\Users\louise\AppData\Roaming\Mozilla\Firefox\Profiles\fyn8wgqc.default E5AF72B7353FF8D431A7C463A4229524 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll - Shockwave Flash 2616B4D6D04F18C579B7861F02B0B592 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.130.20 369EC92E676537A3F86C5074BA30FC96 - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System ==== Fake Chromium Profiles Check ====================== Fake profile C:\Users\Administrator\AppData\Local\Torch deleted Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome deleted Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome SxS deleted Fake profile C:\Users\Administrator\AppData\Local\Comodo\Dragon deleted Fake profile C:\Users\Gast\AppData\Local\Torch deleted Fake profile C:\Users\Gast\AppData\Local\Google\Chrome SxS deleted Fake profile C:\Users\Gast\AppData\Local\Comodo\Dragon deleted Fake profile C:\Users\HomeGroupUser$\AppData\Local\Torch deleted Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome deleted Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS deleted Fake profile C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon deleted Fake profile C:\Users\louise\AppData\Local\Torch deleted Fake profile C:\Users\louise\AppData\Local\Google\Chrome SxS deleted Fake profile C:\Users\louise\AppData\Local\Comodo\Dragon deleted ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions oilkkkefbalmbfppgjmgjoefbclebkce - No path found[] pfkfdlcdbajamklbneflfbcmfgddmpae - No path found[] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions oilkkkefbalmbfppgjmgjoefbclebkce - No path found[] pfkfdlcdbajamklbneflfbcmfgddmpae - No path found[] avast Online Security - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki Facebook Invite Them All - Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\jladghljinmlokelojmdmblikkifabea BrowseStudio - louise\AppData\Local\Google\Chrome\User Data\Default\Extensions\fappblnaebeochecpgnolonpeplcpkig Facebook Invite Them All - louise\AppData\Local\Google\Chrome\User Data\Default\Extensions\jladghljinmlokelojmdmblikkifabea ==== Chromium Startpages ====================== C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Preferences "homepage": "[url]http://Vosteran.com/?f=1&a=vst_ir_14_46_ch&cd=2XzuyEtN2Y1L1Qzu0B0AyByCtA0F0CtAtDyE0Azy0EyByEtAtN0D0Tzu0StCtDyDtDtN1L2XzutAtFyCtFyEtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAtC0BtBtDtB0ByDtGtDyBtCyBtGtC0C0D0CtGyEzz0EtCtGyDyDyC0F0CtCyC0AyCyEzz0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzzztA0EzzyC0C0EtGyEyB0EtBtGyEzzyEyBtGzz0BtA0AtGtCtB0B0E0AtDtByDtBtDyE0B2Q&cr=917827958&ir=[/url]", "startup_urls": [ "[url]http://Vosteran.com/?f=7&a=vst_ir_14_46_ch&cd=2XzuyEtN2Y1L1Qzu0B0AyByCtA0F0CtAtDyE0Azy0EyByEtAtN0D0Tzu0StCtDyDtDtN1L2XzutAtFyCtFyEtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAtC0BtBtDtB0ByDtGtDyBtCyBtGtC0C0D0CtGyEzz0EtCtGyDyDyC0F0CtCyC0AyCyEzz0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzzztA0EzzyC0C0EtGyEyB0EtBtGyEzzyEyBtGzz0BtA0AtGtCtB0B0E0AtDtByDtBtDyE0B2Q&cr=917827958&ir=[/url]", "[url]http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX[/url]" ], ==== Chromium Fix ====================== C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_[url="http://www.superfish.com_0.localstorage"]www.superfish.com_0.localstorage[/url] deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_[url="http://www.superfish.com_0.localstorage-journal"]www.superfish.com_0.localstorage-journal[/url] deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_[url="http://www.superfish.com_0.localstorage"]www.superfish.com_0.localstorage[/url] deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_[url="http://www.superfish.com_0.localstorage-journal"]www.superfish.com_0.localstorage-journal[/url] deleted successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_[url="http://www.superfish.com_0.localstorage"]www.superfish.com_0.localstorage[/url] deleted successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_[url="http://www.superfish.com_0.localstorage-journal"]www.superfish.com_0.localstorage-journal[/url] deleted successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_[url="http://www.superfish.com_0.localstorage"]www.superfish.com_0.localstorage[/url] deleted successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_[url="http://www.superfish.com_0.localstorage-journal"]www.superfish.com_0.localstorage-journal[/url] deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.amaizingsearches.info_0.localstorage deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.amaizingsearches.info_0.localstorage-journal deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage-journal deleted successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage deleted successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage-journal deleted successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage deleted successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage-journal deleted successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_[url="http://www.great-save.com_0.localstorage"]www.great-save.com_0.localstorage[/url] deleted successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_[url="http://www.great-save.com_0.localstorage-journal"]www.great-save.com_0.localstorage-journal[/url] deleted successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\jladghljinmlokelojmdmblikkifabea deleted successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Extensions\jladghljinmlokelojmdmblikkifabea deleted successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jladghljinmlokelojmdmblikkifabea_0.localstorage deleted successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jladghljinmlokelojmdmblikkifabea_0.localstorage-journal deleted successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Extensions\fappblnaebeochecpgnolonpeplcpkig deleted successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fappblnaebeochecpgnolonpeplcpkig_0.localstorage deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="[url]http://Vosteran.com/?f=1&a=vst_ir_14_46_ch&cd=2XzuyEtN2Y1L1Qzu0B0AyByCtA0F0CtAtDyE0Azy0EyByEtAtN0D0Tzu0StCtDyDtDtN1L2XzutAtFyCtFyEtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAtC0BtBtDtB0ByDtGtDyBtCyBtGtC0C0D0CtGyEzz0EtCtGyDyDyC0F0CtCyC0AyCyEzz0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzzztA0EzzyC0C0EtGyEyB0EtBtGyEzzyEyBtGzz0BtA0AtGtCtB0B0E0AtDtByDtBtDyE0B2Q&cr=917827958&ir=[/url]" "Search Page"="[url]http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}[/url]" "Default_Page_URL"="[url]http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX[/url]" "Search Bar"="[url]http://www.google.com/ie[/url]" "Default_Search_URL"="[url]http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}[/url]" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="[url]http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}[/url]" "Default_Page_URL"="[url]http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX[/url]" "Start Page"="[url]http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX[/url]" "Search Page"="[url]http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}[/url]" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="[url]http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}[/url]" "Default_Page_URL"="[url]http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX[/url]" "Start Page"="[url]http://www.mystartsearch.com/?type=hp&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX[/url]" "Search Page"="[url]http://www.mystartsearch.com/web/?type=ds&ts=1416127417&from=wpc&uid=HGSTXHTS545050A7E380_130526TE8513L90PMGVPX&q={searchTerms}[/url]" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] @="[url]http://www.google.com/search?q=%s[/url]" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "SearchAssistant"="[url]http://www.google.com/ie[/url]" "Default_Search_URL"="[url]http://www.google.com/ie[/url]" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="[url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]" "Search Bar"="[url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]" "Default_Search_URL"="[url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]" "Default_Page_URL"="[url]http://go.microsoft.com/fwlink/?LinkId=69157[/url]" "Start Page"="[url]http://Vosteran.com/?f=1&a=vst_ir_14_46_ch&cd=2XzuyEtN2Y1L1Qzu0B0AyByCtA0F0CtAtDyE0Azy0EyByEtAtN0D0Tzu0StCtDyDtDtN1L2XzutAtFyCtFyEtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAtC0BtBtDtB0ByDtGtDyBtCyBtGtC0C0D0CtGyEzz0EtCtGyDyDyC0F0CtCyC0AyCyEzz0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzzztA0EzzyC0C0EtGyEyB0EtBtGyEzzyEyBtGzz0BtA0AtGtCtB0B0E0AtDtByDtBtDyE0B2Q&cr=917827958&ir=[/url]" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="[url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]" "Search Page"="[url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]" "Default_Page_URL"="[url]http://go.microsoft.com/fwlink/?LinkId=69157[/url]" "Start Page"="[url]http://go.microsoft.com/fwlink/?LinkId=69157[/url]" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="[url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]" "Search Page"="[url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]" "Default_Page_URL"="[url]http://go.microsoft.com/fwlink/?LinkId=69157[/url]" "Start Page"="[url]http://go.microsoft.com/fwlink/?LinkId=69157[/url]" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="[url]http://search.msn.com/results.asp?q=%s[/url]" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="[url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]" "SearchAssistant"="[url]http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm[/url]" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {012E1000-F331-11DB-8314-0800200C9A66} Google Url="[url]http://www.google.com/search?q={searchTerms}[/url]" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="[url]http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC[/url]" {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} Vosteran Url="[url]http://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ir_14_46_ch&cd=2XzuyEtN2Y1L1Qzu0B0AyByCtA0F0CtAtDyE0Azy0EyByEtAtN0D0Tzu0StCtDyDtDtN1L2XzutAtFyCtFyEtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StAtC0BtBtDtB0ByDtGtDyBtCyBtGtC0C0D0CtGyEzz0EtCtGyDyDyC0F0CtCyC0AyCyEzz0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzzzztA0EzzyC0C0EtGyEyB0EtBtGyEzzyEyBtGzz0BtA0AtGtCtB0B0E0AtDtByDtBtDyE0B2Q&cr=917827958&ir=[/url]" {3C3FEF63-0EC4-4CFA-8281-367BD6EFCB13} Bing Url="[url]http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02[/url]" {57E80CD9-B9EB-4E52-88B1-78EFAE135B7A} Google Url="[url]http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8[/url]" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Goo Url="[url]http://www.google.com/search?q={sear[/url]" {A5EE07E2-8FF8-49B7-BAA7-AEE84C8D4A3A} eBay Url="[url]http://rover.ebay.com/rover/1/1346-81661-16445-14/4?mpre=http://shop.ebay.nl/?oemInLn=ieSrch-&_nkw={searchTerms}[/url]" ==== Deleting CLSID Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a4b0faf0-9c89-4a85-a1a7-32410f746f0e} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a4b0faf0-9c89-4a85-a1a7-32410f746f0e} deleted successfully HKEY_CLASSES_ROOT\CLSID\{a4b0faf0-9c89-4a85-a1a7-32410f746f0e} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{a4b0faf0-9c89-4a85-a1a7-32410f746f0e} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4b0faf0-9c89-4a85-a1a7-32410f746f0e} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4b0faf0-9c89-4a85-a1a7-32410f746f0e} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\fefc37f1-7a94-4572-95eb-9bff2bdaf278 deleted successfully HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\oilkkkefbalmbfppgjmgjoefbclebkce deleted successfully HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions\pfkfdlcdbajamklbneflfbcmfgddmpae deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{45606A90-3363-3A3B-1C15-C40E77F4DAA0} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{497C131E-2032-051B-B32A-C69A960FBB13} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C87834EB-A2A0-B9D4-AA9A-C263D1191051} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\S-576482620 deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{fc67e7a0} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PC Speed Maximizer_is1 deleted successfully ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gast\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\louise\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\louise\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Gast\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\louise\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\louise\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Gast\AppData\Local\Mozilla\Firefox\Profiles\6288fqoo.default\Cache emptied successfully C:\Users\louise\AppData\Local\Mozilla\Firefox\Profiles\fyn8wgqc.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\louise\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=327 folders=114 113489095 bytes) ==== Empty Temp Folders ====================== C:\Users\Administrator\AppData\Local\Temp emptied successfully C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Gast\AppData\Local\Temp emptied successfully C:\Users\louise\AppData\Local\Temp will be emptied at reboot C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\louise\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\PROGRA~2\BrowseStudio\bin\BrowseStudio.BrowserAdapter64.exe" not found "C:\PROGRA~3\Trusted Publisher" not found "C:\PROGRA~2\BrowseStudio" not found ==== EOF on di 18-11-2014 at 15:32:57,00 ====================== [/QUOTE]
Insert quotes…
Verification
Post reply
Top