Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
NiceDEAL,FunShopper,OnlineShopping - Popups, and Extensions in Chrome
Message
<blockquote data-quote="aMochaFrappe" data-source="post: 389715" data-attributes="member: 36639"><p>I also ran a ZOEK test so I'll just attach that here as well if it helps.</p><p></p><p></p><p>Zoek.exe v5.0.0.0 Updated 04-May-2015</p><p>Tool run by Sarah-jane on 25/05/2015 at 16:43:34.66.</p><p>Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64</p><p>Running in: Normal Mode Internet Access Detected</p><p>Launched: C:\Users\Sarah-jane\Desktop\zoek.exe [Scan all users] [Script inserted] </p><p></p><p>==== System Restore Info ======================</p><p></p><p>25/05/2015 4:45:12 PM Zoek.exe System Restore Point Created Successfully.</p><p></p><p>==== Empty Folders Check ======================</p><p></p><p>C:\PROGRA~2\MSXML 4.0 deleted successfully</p><p>C:\PROGRA~3\ALM deleted successfully</p><p>C:\PROGRA~3\boomdeal deleted successfully</p><p>C:\PROGRA~3\Evernote deleted successfully</p><p>C:\PROGRA~3\ZoomBrowser deleted successfully</p><p>C:\Users\Sarah-jane\AppData\Roaming\Publish Providers deleted successfully</p><p>C:\Users\Sarah-jane\AppData\Roaming\Three Rings Design deleted successfully</p><p>C:\Users\Sarah-jane\AppData\Local\Genesis_06030337 deleted successfully</p><p></p><p>==== Deleting CLSID Registry Keys ======================</p><p></p><p></p><p>==== Deleting CLSID Registry Values ======================</p><p></p><p></p><p>==== Deleting Services ======================</p><p></p><p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fa6789c5 deleted successfully</p><p>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\fa6789c5 deleted successfully</p><p></p><p>==== Batch Command(s) Run By Tool======================</p><p></p><p></p><p>==== Deleting Files \ Folders ======================</p><p></p><p>C:\PROGRA~2\ccomparENbuuy deleted</p><p>C:\PROGRA~2\FFunsshoPper deleted</p><p>C:\PROGRA~2\joinntheShop deleted</p><p>C:\PROGRA~2\joIntheshop deleted</p><p>C:\PROGRA~2\VideoCnv deleted</p><p>C:\PROGRA~2\CNN News deleted</p><p>C:\PROGRA~2\compArenubuyy deleted</p><p>C:\PROGRA~2\CRX Inspector deleted</p><p>C:\PROGRA~2\Related Content by Zemanta deleted</p><p>C:\PROGRA~3\bmenojljjafdjphjhegookimnfkngjkb deleted</p><p>C:\PROGRA~3\7733977412527878142 deleted</p><p>C:\PROGRA~3\6b549b7af69e6ffe deleted</p><p>C:\PROGRA~2\Free Video Converter deleted</p><p>C:\Users\Sarah-jane\AppData\Roaming\appdataFr3.bin deleted</p><p>C:\Users\Sarah-jane\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Free Video Converter.lnk deleted</p><p>C:\PROGRA~3\hash.dat deleted</p><p>C:\PROGRA~3\Microsoft\Windows\Start Menu\Programs\Free Video Converter\Free Video Converter.lnk deleted</p><p>C:\PROGRA~3\chepsales4all deleted</p><p>C:\PROGRA~3\funshopper deleted</p><p>C:\PROGRA~3\onlineshopping deleted</p><p>C:\PROGRA~3\dealplug deleted</p><p>C:\PROGRA~3\niceDeal deleted</p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Video Converter deleted</p><p>C:\Windows\wininit.ini deleted</p><p>C:\Windows\SysNative\config\systemprofile\Searches deleted</p><p>C:\Windows\SysWow64\AI_RecycleBin deleted</p><p>C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\<a href="mailto:55c@w.org">55c@w.org</a> deleted</p><p>C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\<a href="mailto:55fiMJwaY@G.com">55fiMJwaY@G.com</a> deleted</p><p>C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\<a href="mailto:62NCSR5@Z.edu">62NCSR5@Z.edu</a> deleted</p><p>C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\<a href="mailto:e@1sRFC4.com">e@1sRFC4.com</a> deleted</p><p>C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\<a href="mailto:g6d@cZI.com">g6d@cZI.com</a> deleted</p><p>C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\<a href="mailto:Qq1ZuAR@Ae6g.net">Qq1ZuAR@Ae6g.net</a> deleted</p><p>C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\<a href="mailto:Y@4e1.edu">Y@4e1.edu</a> deleted</p><p>C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\<a href="mailto:zmcvneH@C.edu">zmcvneH@C.edu</a> deleted</p><p></p><p>==== Firefox Start and Search pages ======================</p><p></p><p>ProfilePath: C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default</p><p>user_pref("browser.startup.homepage", "about:home");</p><p>user_pref("browser.search.defaultenginename.US", "Google");</p><p>user_pref("browser.search.selectedEngine", "Google");</p><p></p><p>==== Firefox Extensions Registry ======================</p><p></p><p>[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]</p><p>"<a href="mailto:online_banking@kaspersky.com">online_banking@kaspersky.com</a>"="C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\<a href="mailto:online_banking@kaspersky.com">online_banking@kaspersky.com</a>" [18/02/2015 02:38 PM]</p><p></p><p>==== Firefox Extensions ======================</p><p></p><p>ProfilePath: C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default</p><p>- Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\<a href="mailto:anti_banner@kaspersky.com">anti_banner@kaspersky.com</a></p><p>- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi</p><p></p><p>AppDir: C:\Program Files (x86)\Mozilla Firefox</p><p>- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}</p><p></p><p>==== Firefox Plugins ======================</p><p></p><p>Profilepath: C:\Users\Sarah-jane\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default</p><p>77887617FA24E755A5A431E3E28E25E1 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll - Shockwave for Director / Shockwave for Director</p><p>9AE02005247DA91AB1743F5208DBEF76 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll - Shockwave Flash</p><p></p><p></p><p>==== Chromium Look ======================</p><p></p><p>Google Chrome Version: 43.0.2357.65</p><p></p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions</p><p>dchlnpcodkpfdpacogkljefecpegganj - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\urladvisor.crx[11/11/2013 10:21 PM]</p><p>lpoimibckejjdjcfbdnajaicnklhfplh - <a href="https://chrome.google.com/webstore/detail/lpoimibckejjdjcfbdnajaicnklhfplh[]" target="_blank">https://chrome.google.com/webstore/detail/lpoimibckejjdjcfbdnajaicnklhfplh[]</a></p><p>pjldcfjmnllhmgjclecdnfampinooman - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\ab.crx[11/11/2013 10:21 PM]</p><p></p><p>AdBlock - Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom</p><p>Bookmark Manager DEV - Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik</p><p></p><p>==== Chromium Startpages ======================</p><p></p><p>C:\Users\Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Preferences</p><p>"restore_on_startup":"798733F49916105E3A72E90A170DF01CEA19CDC6E427F7985C5865801BAE1626","startup_urls":"B84B09C39BA5B1F9FAD8F82D15E660AC79077507E325DF1F740AD901CA5582F5"},"software_reporter":{"prompt_reason":"0B68E5EAA12276BA6ECE82483D3171D35449587208FBFE5F2B39100AC33C3F05","prompt_seed":"C6E0D51DE91EF68B63923D62A127BA76AD1AE67A9AB185583BD2C7D5F02B8DF4","prompt_version":"E593147F92C95F743DF3116E7D91F59567E172E5B07301876E55D358ED502FC9"},"sync":{"remaining_rollback_tries":"A977A4A520DC1D864AB66C2377604CBBE4B84B0DBC7CB676CAAAFC06EF7CFD87"}},"super_mac":"629C4B092A7F368C0A034EAC3B261EEA5DA7624A5EDC74F07D6C1EF451B4E3D5"},"safebrowsing":{"incidents_sent":{"2":{"chrome.dll":"3774509266","chrome_child.dll":"3743713718"},"6":{"script_request_incident":"42"}}},"session":{"startup_urls":["<a href="http://search.conduit.com/?SearchSource=10&ctid=CT2653012&UP=SPE505EBCE-4A88-41E8-AEB1-97705BB278A4&SSPV=" target="_blank">http://search.conduit.com/?SearchSource=10&ctid=CT2653012&UP=SPE505EBCE-4A88-41E8-AEB1-97705BB278A4&SSPV=</a>","<a href="https://multi.eldancall.com/admin" target="_blank">https://multi.eldancall.com/admin</a>","<a href="http://gmail.com/" target="_blank">http://gmail.com/</a>"]},"sync":{"remaining_rollback_tries":0}}</p><p></p><p></p><p>==== Chromium Fix ======================</p><p></p><p>C:\Users\Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_<a href="http://www.azlyrics.com_0.localstorage" target="_blank">www.azlyrics.com_0.localstorage</a> deleted successfully</p><p>C:\Users\Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_<a href="http://www.azlyrics.com_0.localstorage-journal" target="_blank">www.azlyrics.com_0.localstorage-journal</a> deleted successfully</p><p>C:\Users\Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage deleted successfully</p><p>C:\Users\Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully</p><p></p><p>==== Set IE to Default ======================</p><p></p><p>Old Values:</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]</p><p>"Start Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank" target="_blank">http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank</a>"</p><p>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]</p><p>"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"</p><p></p><p>New Values:</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]</p><p>"Start Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank" target="_blank">http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank</a>"</p><p>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]</p><p>"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"</p><p></p><p>==== All HKCU SearchScopes ======================</p><p></p><p>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes</p><p>{012E1000-F331-11DB-8314-0800200C9A66} Google Url="<a href="http://www.google.com/search?q={searchTerms}" target="_blank">http://www.google.com/search?q={searchTerms}</a>"</p><p>{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="<a href="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" target="_blank">http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC</a>"</p><p></p><p>==== Deleting CLSID Registry Keys ======================</p><p></p><p>HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{046580FD-86C8-4885-9D49-DEACF0A96859} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{046580FD-86C8-4885-9D49-DEACF0A96859} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{51D646D1-4956-4F71-8AA8-D7E16C425E67} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{51D646D1-4956-4F71-8AA8-D7E16C425E67} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{94519C9A-B4BA-4849-A10B-8B1C19840C84} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{94519C9A-B4BA-4849-A10B-8B1C19840C84} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C08C1868-D8E4-4D14-B4C7-C831C2537B9D} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C08C1868-D8E4-4D14-B4C7-C831C2537B9D} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E0047D16-B990-4FE7-9A65-E749ACBF08D9} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E0047D16-B990-4FE7-9A65-E749ACBF08D9} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{046580FD-86C8-4885-9D49-DEACF0A96859} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{046580FD-86C8-4885-9D49-DEACF0A96859} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{046580FD-86C8-4885-9D49-DEACF0A96859} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{046580FD-86C8-4885-9D49-DEACF0A96859} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{51D646D1-4956-4F71-8AA8-D7E16C425E67} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{51D646D1-4956-4F71-8AA8-D7E16C425E67} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{51D646D1-4956-4F71-8AA8-D7E16C425E67} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{51D646D1-4956-4F71-8AA8-D7E16C425E67} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{94519C9A-B4BA-4849-A10B-8B1C19840C84} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{94519C9A-B4BA-4849-A10B-8B1C19840C84} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{94519C9A-B4BA-4849-A10B-8B1C19840C84} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{94519C9A-B4BA-4849-A10B-8B1C19840C84} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C08C1868-D8E4-4D14-B4C7-C831C2537B9D} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C08C1868-D8E4-4D14-B4C7-C831C2537B9D} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{C08C1868-D8E4-4D14-B4C7-C831C2537B9D} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{C08C1868-D8E4-4D14-B4C7-C831C2537B9D} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E0047D16-B990-4FE7-9A65-E749ACBF08D9} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E0047D16-B990-4FE7-9A65-E749ACBF08D9} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{E0047D16-B990-4FE7-9A65-E749ACBF08D9} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{E0047D16-B990-4FE7-9A65-E749ACBF08D9} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully</p><p></p><p>==== Deleting CLSID Registry Values ======================</p><p></p><p></p><p>==== Deleting Registry Keys ======================</p><p></p><p>HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{fa6789c5} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Free Video Converter_is1 deleted successfully</p><p></p><p>==== Empty IE Cache ======================</p><p></p><p>C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Users\Sarah-jane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Users\Sarah-jane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully</p><p>C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p></p><p>==== Empty FireFox Cache ======================</p><p></p><p>C:\Users\Sarah-jane\AppData\Local\Mozilla\Firefox\Profiles\og3k1l3g.default\cache2 emptied successfully</p><p></p><p>==== Empty Chrome Cache ======================</p><p></p><p>C:\Users\Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully</p><p></p><p>==== Empty All Flash Cache ======================</p><p></p><p>Flash Cache Emptied Successfully</p><p></p><p>==== Empty All Java Cache ======================</p><p></p><p>Java Cache cleared successfully</p><p></p><p>==== C:\zoek_backup content ======================</p><p></p><p>C:\zoek_backup (files=369 folders=43 20663355 bytes)</p><p></p><p>==== Empty Temp Folders ======================</p><p></p><p>C:\Users\Default\AppData\Local\Temp emptied successfully</p><p>C:\Users\Default User\AppData\Local\Temp emptied successfully</p><p>C:\Users\Sarah-jane\AppData\Local\Temp will be emptied at reboot</p><p>C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully</p><p>C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully</p><p>C:\Windows\Temp will be emptied at reboot</p><p></p><p>==== After Reboot ======================</p><p></p><p>==== Empty Temp Folders ======================</p><p></p><p>C:\Windows\Temp successfully emptied</p><p>C:\Users\SARAH-~1\AppData\Local\Temp successfully emptied</p><p></p><p>==== Empty Recycle Bin ======================</p><p></p><p>C:\$RECYCLE.BIN successfully emptied</p><p></p><p>==== EOF on 25/05/2015 at 17:08:34.54 ======================</p></blockquote><p></p>
[QUOTE="aMochaFrappe, post: 389715, member: 36639"] I also ran a ZOEK test so I'll just attach that here as well if it helps. Zoek.exe v5.0.0.0 Updated 04-May-2015 Tool run by Sarah-jane on 25/05/2015 at 16:43:34.66. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Sarah-jane\Desktop\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 25/05/2015 4:45:12 PM Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\PROGRA~2\MSXML 4.0 deleted successfully C:\PROGRA~3\ALM deleted successfully C:\PROGRA~3\boomdeal deleted successfully C:\PROGRA~3\Evernote deleted successfully C:\PROGRA~3\ZoomBrowser deleted successfully C:\Users\Sarah-jane\AppData\Roaming\Publish Providers deleted successfully C:\Users\Sarah-jane\AppData\Roaming\Three Rings Design deleted successfully C:\Users\Sarah-jane\AppData\Local\Genesis_06030337 deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fa6789c5 deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\fa6789c5 deleted successfully ==== Batch Command(s) Run By Tool====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~2\ccomparENbuuy deleted C:\PROGRA~2\FFunsshoPper deleted C:\PROGRA~2\joinntheShop deleted C:\PROGRA~2\joIntheshop deleted C:\PROGRA~2\VideoCnv deleted C:\PROGRA~2\CNN News deleted C:\PROGRA~2\compArenubuyy deleted C:\PROGRA~2\CRX Inspector deleted C:\PROGRA~2\Related Content by Zemanta deleted C:\PROGRA~3\bmenojljjafdjphjhegookimnfkngjkb deleted C:\PROGRA~3\7733977412527878142 deleted C:\PROGRA~3\6b549b7af69e6ffe deleted C:\PROGRA~2\Free Video Converter deleted C:\Users\Sarah-jane\AppData\Roaming\appdataFr3.bin deleted C:\Users\Sarah-jane\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Free Video Converter.lnk deleted C:\PROGRA~3\hash.dat deleted C:\PROGRA~3\Microsoft\Windows\Start Menu\Programs\Free Video Converter\Free Video Converter.lnk deleted C:\PROGRA~3\chepsales4all deleted C:\PROGRA~3\funshopper deleted C:\PROGRA~3\onlineshopping deleted C:\PROGRA~3\dealplug deleted C:\PROGRA~3\niceDeal deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Video Converter deleted C:\Windows\wininit.ini deleted C:\Windows\SysNative\config\systemprofile\Searches deleted C:\Windows\SysWow64\AI_RecycleBin deleted C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\[email]55c@w.org[/email] deleted C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\[email]55fiMJwaY@G.com[/email] deleted C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\[email]62NCSR5@Z.edu[/email] deleted C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\[email]e@1sRFC4.com[/email] deleted C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\[email]g6d@cZI.com[/email] deleted C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\[email]Qq1ZuAR@Ae6g.net[/email] deleted C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\[email]Y@4e1.edu[/email] deleted C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default\extensions\[email]zmcvneH@C.edu[/email] deleted ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default user_pref("browser.startup.homepage", "about:home"); user_pref("browser.search.defaultenginename.US", "Google"); user_pref("browser.search.selectedEngine", "Google"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "[email]online_banking@kaspersky.com[/email]"="C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[email]online_banking@kaspersky.com[/email]" [18/02/2015 02:38 PM] ==== Firefox Extensions ====================== ProfilePath: C:\Users\SARAH-~1\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default - Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\FFExt\[email]anti_banner@kaspersky.com[/email] - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Sarah-jane\AppData\Roaming\Mozilla\Firefox\Profiles\og3k1l3g.default 77887617FA24E755A5A431E3E28E25E1 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll - Shockwave for Director / Shockwave for Director 9AE02005247DA91AB1743F5208DBEF76 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll - Shockwave Flash ==== Chromium Look ====================== Google Chrome Version: 43.0.2357.65 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions dchlnpcodkpfdpacogkljefecpegganj - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\urladvisor.crx[11/11/2013 10:21 PM] lpoimibckejjdjcfbdnajaicnklhfplh - [URL]https://chrome.google.com/webstore/detail/lpoimibckejjdjcfbdnajaicnklhfplh[][/URL] pjldcfjmnllhmgjclecdnfampinooman - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 3.0\ChromeExt\ab.crx[11/11/2013 10:21 PM] AdBlock - Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom Bookmark Manager DEV - Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik ==== Chromium Startpages ====================== C:\Users\Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Preferences "restore_on_startup":"798733F49916105E3A72E90A170DF01CEA19CDC6E427F7985C5865801BAE1626","startup_urls":"B84B09C39BA5B1F9FAD8F82D15E660AC79077507E325DF1F740AD901CA5582F5"},"software_reporter":{"prompt_reason":"0B68E5EAA12276BA6ECE82483D3171D35449587208FBFE5F2B39100AC33C3F05","prompt_seed":"C6E0D51DE91EF68B63923D62A127BA76AD1AE67A9AB185583BD2C7D5F02B8DF4","prompt_version":"E593147F92C95F743DF3116E7D91F59567E172E5B07301876E55D358ED502FC9"},"sync":{"remaining_rollback_tries":"A977A4A520DC1D864AB66C2377604CBBE4B84B0DBC7CB676CAAAFC06EF7CFD87"}},"super_mac":"629C4B092A7F368C0A034EAC3B261EEA5DA7624A5EDC74F07D6C1EF451B4E3D5"},"safebrowsing":{"incidents_sent":{"2":{"chrome.dll":"3774509266","chrome_child.dll":"3743713718"},"6":{"script_request_incident":"42"}}},"session":{"startup_urls":["[URL]http://search.conduit.com/?SearchSource=10&ctid=CT2653012&UP=SPE505EBCE-4A88-41E8-AEB1-97705BB278A4&SSPV=[/URL]","[URL]https://multi.eldancall.com/admin[/URL]","[URL]http://gmail.com/[/URL]"]},"sync":{"remaining_rollback_tries":0}} ==== Chromium Fix ====================== C:\Users\Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_[URL="http://www.azlyrics.com_0.localstorage"]www.azlyrics.com_0.localstorage[/URL] deleted successfully C:\Users\Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_[URL="http://www.azlyrics.com_0.localstorage-journal"]www.azlyrics.com_0.localstorage-journal[/URL] deleted successfully C:\Users\Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage deleted successfully C:\Users\Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="[URL]http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank[/URL]" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="[URL]http://go.microsoft.com/fwlink/?LinkId=56626&homepage=about:blank[/URL]" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {012E1000-F331-11DB-8314-0800200C9A66} Google Url="[URL]http://www.google.com/search?q={searchTerms}[/URL]" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="[URL]http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC[/URL]" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{046580FD-86C8-4885-9D49-DEACF0A96859} deleted successfully HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{046580FD-86C8-4885-9D49-DEACF0A96859} deleted successfully HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{51D646D1-4956-4F71-8AA8-D7E16C425E67} deleted successfully HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{51D646D1-4956-4F71-8AA8-D7E16C425E67} deleted successfully HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{94519C9A-B4BA-4849-A10B-8B1C19840C84} deleted successfully HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{94519C9A-B4BA-4849-A10B-8B1C19840C84} deleted successfully HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C08C1868-D8E4-4D14-B4C7-C831C2537B9D} deleted successfully HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C08C1868-D8E4-4D14-B4C7-C831C2537B9D} deleted successfully HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E0047D16-B990-4FE7-9A65-E749ACBF08D9} deleted successfully HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E0047D16-B990-4FE7-9A65-E749ACBF08D9} deleted successfully HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully HKEY_USERS\S-1-5-21-3228432307-2206631168-340998649-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{046580FD-86C8-4885-9D49-DEACF0A96859} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{046580FD-86C8-4885-9D49-DEACF0A96859} deleted successfully HKEY_CLASSES_ROOT\CLSID\{046580FD-86C8-4885-9D49-DEACF0A96859} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{046580FD-86C8-4885-9D49-DEACF0A96859} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{51D646D1-4956-4F71-8AA8-D7E16C425E67} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{51D646D1-4956-4F71-8AA8-D7E16C425E67} deleted successfully HKEY_CLASSES_ROOT\CLSID\{51D646D1-4956-4F71-8AA8-D7E16C425E67} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{51D646D1-4956-4F71-8AA8-D7E16C425E67} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{94519C9A-B4BA-4849-A10B-8B1C19840C84} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{94519C9A-B4BA-4849-A10B-8B1C19840C84} deleted successfully HKEY_CLASSES_ROOT\CLSID\{94519C9A-B4BA-4849-A10B-8B1C19840C84} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{94519C9A-B4BA-4849-A10B-8B1C19840C84} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C08C1868-D8E4-4D14-B4C7-C831C2537B9D} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C08C1868-D8E4-4D14-B4C7-C831C2537B9D} deleted successfully HKEY_CLASSES_ROOT\CLSID\{C08C1868-D8E4-4D14-B4C7-C831C2537B9D} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{C08C1868-D8E4-4D14-B4C7-C831C2537B9D} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E0047D16-B990-4FE7-9A65-E749ACBF08D9} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E0047D16-B990-4FE7-9A65-E749ACBF08D9} deleted successfully HKEY_CLASSES_ROOT\CLSID\{E0047D16-B990-4FE7-9A65-E749ACBF08D9} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{E0047D16-B990-4FE7-9A65-E749ACBF08D9} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully HKEY_CLASSES_ROOT\CLSID\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5eb3f618-2ee4-4923-b21b-b5d760a94a0f} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully HKEY_CLASSES_ROOT\CLSID\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{df09fce2-a22f-49f6-a8b0-ee3ab86e05e0} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{fa6789c5} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Free Video Converter_is1 deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Sarah-jane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Sarah-jane\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Sarah-jane\AppData\Local\Mozilla\Firefox\Profiles\og3k1l3g.default\cache2 emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Sarah-jane\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=369 folders=43 20663355 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Sarah-jane\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\SARAH-~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on 25/05/2015 at 17:08:34.54 ====================== [/QUOTE]
Insert quotes…
Verification
Post reply
Top