Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
SafeSearch enforced by administrator in Google Chrome, cannot be removed
Message
<blockquote data-quote="celloxsaurus" data-source="post: 397229" data-attributes="member: 37046"><p>I apologize for the delay in responding. Here is the log file you requested.</p><p></p><p>edit: attempting to upload the file itself throws an error (the file is empty); here is the content of the file:</p><p></p><p></p><p>Zoek.exe v5.0.0.0 Updated 04-May-2015</p><p>Tool run by Lise Marie on Fri 06/12/2015 at 21:50:16.90.</p><p>Microsoft Windows 8 6.2.9200 x64</p><p>Running in: Normal Mode Internet Access Detected</p><p>Launched: C:\Users\Lise Marie\Downloads\zoek.exe [Scan all users] [Script inserted] </p><p></p><p>==== System Restore Info ======================</p><p></p><p>6/12/2015 9:52:22 PM Zoek.exe System Restore Point Created Successfully.</p><p></p><p>==== Empty Folders Check ======================</p><p></p><p>C:\PROGRA~2\Amazon deleted successfully</p><p>C:\PROGRA~2\Errors deleted successfully</p><p>C:\PROGRA~2\SafeConnect deleted successfully</p><p>C:\PROGRA~2\The Weather Channel FW deleted successfully</p><p>C:\PROGRA~2\COMMON~1\supportdotcom deleted successfully</p><p>C:\Users\Lise Marie\AppData\Local\Component deleted successfully</p><p>C:\Users\Lise Marie\AppData\Local\StormAlerts deleted successfully</p><p></p><p>==== Deleting CLSID Registry Keys ======================</p><p></p><p>HKEY_USERS\S-1-5-21-4272160834-3168868320-1750411223-1001\Software\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5} deleted successfully</p><p>HKEY_USERS\S-1-5-21-4272160834-3168868320-1750411223-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{814FEF07-4D9D-40C8-9721-59711B2045C1} deleted successfully</p><p>HKEY_USERS\S-1-5-21-4272160834-3168868320-1750411223-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{839AB207-35B9-4D10-B707-3038D88D0EDD} deleted successfully</p><p>HKEY_USERS\S-1-5-21-4272160834-3168868320-1750411223-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4E39681-15F8-4fda-B8A3-B5C98378F2F3} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5} deleted successfully</p><p></p><p>==== Deleting CLSID Registry Values ======================</p><p></p><p></p><p>==== Deleting Services ======================</p><p></p><p></p><p>==== Registry Fix Code ======================</p><p></p><p>Windows Registry Editor Version 5.00</p><p></p><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command]</p><p>@="C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe"</p><p>[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command]</p><p>@="C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe"</p><p></p><p>==== Batch Command(s) Run By Tool======================</p><p></p><p></p><p>==== Deleting Files \ Folders ======================</p><p></p><p>C:\PROGRA~2\Amazon not found</p><p>C:\PROGRA~2\Errors not found</p><p>C:\PROGRA~2\SafeConnect not found</p><p>C:\PROGRA~2\The Weather Channel FW not found</p><p>C:\PROGRA~2\The Weather Channel deleted</p><p>C:\Users\Lise Marie\AppData\Roaming\Scorch_Install.log deleted</p><p>C:\PROGRA~3\eBay deleted</p><p>C:\PROGRA~3\Package Cache deleted</p><p>C:\Users\Lise Marie\AppData\Local\CRE deleted</p><p>C:\windows\SysNative\Tasks\avastBCLRestartS-1-5-21-4272160834-3168868320-1750411223-1001 deleted</p><p>C:\windows\SysNative\Tasks\avastBCLRestart_chrome.exe deleted</p><p>C:\windows\SysNative\GroupPolicy\Machine deleted</p><p>C:\windows\SysNative\GroupPolicy\User deleted</p><p>C:\windows\SysNative\GroupPolicy\GPT.INI deleted</p><p>C:\windows\Syswow64\GroupPolicy\gpt.ini deleted</p><p>C:\windows\SysWow64\AI_RecycleBin deleted</p><p></p><p>==== Firefox Start and Search pages ======================</p><p></p><p>ProfilePath: C:\Users\LISEMA~1\AppData\Roaming\Mozilla\Firefox\Profiles\br8kvdch.default</p><p>user_pref("browser.startup.homepage", "<a href="https://www.google.com/?trackid=sp-006" target="_blank">https://www.google.com/?trackid=sp-006</a>");</p><p>user_pref("browser.search.defaulturl", "<a href="https://www.google.com/search/?trackid=sp-006" target="_blank">https://www.google.com/search/?trackid=sp-006</a>");</p><p>user_pref("browser.search.defaultengine", "Google (avast)");</p><p>user_pref("browser.search.defaultenginename", "Google (avast)");</p><p>user_pref("browser.search.selectedEngine", "Google (avast)");</p><p>user_pref("keyword.URL", "<a href="https://www.google.com/search/?trackid=sp-006" target="_blank">https://www.google.com/search/?trackid=sp-006</a>");</p><p>user_pref("keyword.url", "<a href="http://www.safesear.ch/web/?type=ss-ff-kw&q=" target="_blank">http://www.safesear.ch/web/?type=ss-ff-kw&q=</a>");</p><p></p><p>==== Firefox Extensions Registry ======================</p><p></p><p>[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]</p><p>"<a href="mailto:wrc@avast.com">wrc@avast.com</a>"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [02/21/2015 03:24 PM]</p><p></p><p>==== Firefox Extensions ======================</p><p></p><p>AppDir: C:\Program Files (x86)\Mozilla Firefox</p><p>- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}</p><p></p><p>==== Firefox Plugins ======================</p><p></p><p>Profilepath: C:\Users\Lise Marie\AppData\Roaming\Mozilla\Firefox\Profiles\br8kvdch.default</p><p>08ACECEB47FAF053C468D8AFE44709AD - C:\Users\Lise Marie\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll - Google Update</p><p>49D429EBF5305FC9ADD7545B7C914333 - C:\Users\Lise Marie\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll - Google Talk Plugin</p><p>6BEAD7859E8A087BE04556AB5A78855C - C:\Users\Lise Marie\AppData\Roaming\Mozilla\plugins\npo1d.dll - Google Talk Plugin Video Renderer</p><p>C899B98999270821EDFFA56044DE2377 - C:\Users\Lise Marie\AppData\Roaming\raidcall\plugins\nprcplugin.dll - Raidcall plugin</p><p>FEF9ECECFA177AEC0F7564A08394D2C8 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll - RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit)</p><p>0ABF093757E9C827E30EC652868E5FAC - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll - RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit)</p><p>06E140A567B8DC7900173197FD059EE5 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll - RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit)</p><p>558270B968CB82196CB8D045D13B0FF6 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll - RealDownloader Plugin</p><p></p><p></p><p>==== Chromium Look ======================</p><p></p><p>Google Chrome Version: 43.0.2357.124</p><p></p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions</p><p>gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[12/01/2014 01:33 AM]</p><p>idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[11/29/2012 09:35 PM]</p><p></p><p>Avast Online Security - Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki</p><p>Chrome Hotword Shared Module - Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg</p><p></p><p>==== Chromium Startpages ======================</p><p></p><p>C:\Users\Lise Marie\AppData\Local\Fast Browser\User Data\Default\Preferences</p><p>"homepage": "<a href="http://www.safesear.ch/?type=20150609" target="_blank">http://www.safesear.ch/?type=20150609</a>",</p><p>"startup_urls": [ "<a href="http://www.safesear.ch/?type=20150609" target="_blank">http://www.safesear.ch/?type=20150609</a>" ],</p><p>"urls_to_restore_on_startup": [ "<a href="http://www.safesear.ch/?type=20150609" target="_blank">http://www.safesear.ch/?type=20150609</a>" ]</p><p></p><p>C:\Users\Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Preferences</p><p>imaahmaaome":"E7BA8F30FD44E67901DE959C7A9CF4F576AD3A6DAB3FD14760ACB4DE9F1B84D8","nmmhkkegccagdldgiimedpiccmgmieda":"58B6BDE35EA09B8B3AA6CD267D926B7C6E8E72D53907BC34CA827D323C32D008","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"29F4C6BE6DB6D4F04B922CD88F77D6665F062E525CA7EBEC654710C5FA7D1602"}},"google":{"services":{"last_username":"873143D4F9AC99735C4AA2DE5752A36358D823698C23531FBEAF78653C2A6420","username":"AE5970C01B69F0636822443E93C8D011415E9BB340A26F608C19F104D827578E"}},"homepage":"3042A70A480F6F993D0F2714AADE08D68F4A85A195CBD151549D347C291FF33D","homepage_is_newtabpage":"F6BD04CEC1E1FBECB3E1B66497AFBC51A7E2613776ABB452C4F9D4502AEEC1A4","pinned_tabs":"21C7811A6CA1296A533EB7401FAA4D22841B769E736E4028C882B335E4CDE857","prefs":{"preference_reset_time":"A922F20D6CF2E83237784DAF430E1A142181ECED93D2647F81118D2C3BB8C3CA"},"profile":{"reset_prompt_memento":"79947232471C57AAF3BE0C4261C554C4C3F2F87539B47349D26526DF4A91595E"},"safebrowsing":{"incidents_sent":"E703B6B25254C0366E49DD7D5CAF85537446AC2595A61993C96B330E1D09468C"},"search_provider_overrides":"39AC5543DC9FF1BD42123B1E784F31FB3092D3F963DE0EEE9D68F1FF26563BFE","session":{"restore_on_startup":"CAB0A1C0598D64E57732FFC3FF391C512787D181A7BE07E0703A43769B08062D","startup_urls":"3BABF93F5300FD9E131C2EFF113091EEEEDDB468A31D8AB716390AAE1BA19974"},"software_reporter":{"prompt_reason":"32748ACDD47BD4841A6698B1E78174F5547E12B0C518D354EA86C9D528C97C33","prompt_seed":"FA66EB38B726A33AF523D8927B4CD55C4910ED3B4C21EEBA2D73D89675319B7F","prompt_version":"0F2886C329593BDFB58961F50D05B802F740678E37BFBB6B2E8FA0535A200888"},"sync":{"remaining_rollback_tries":"C566C66369E0276D3351166E703C512B4CF59B330DB1E142DD1842E9A9941FBB"}},"super_mac":"34F8FCA197626FC15B77B411D735580D142F91D7553D9963F08D04F6A322C9E1"},"session":{"restore_on_startup":4,"startup_urls":["<a href="http://www.google.com/" target="_blank">http://www.google.com/</a>","<a href="http://www.msn.com/?pc=AV01" target="_blank">http://www.msn.com/?pc=AV01</a>"]},"software_reporter":{"prompt_reason":0,"prompt_seed":"20150601","prompt_version":"3.21.0"},"sync":{"remaining_rollback_tries":0}}</p><p></p><p></p><p>==== Chromium Fix ======================</p><p></p><p>C:\Users\Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage deleted successfully</p><p>C:\Users\Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully</p><p>C:\Users\Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_services2.capitalone.com_0.localstorage deleted successfully</p><p>C:\Users\Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_services2.capitalone.com_0.localstorage-journal deleted successfully</p><p></p><p>==== Set IE to Default ======================</p><p></p><p>Old Values:</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]</p><p>"Start Page"="<a href="https://www.google.com/?trackid=sp-006" target="_blank">https://www.google.com/?trackid=sp-006</a>"</p><p>"Search Page"="<a href="https://www.google.com/search?trackid=sp-006&q={searchTerms}" target="_blank">https://www.google.com/search?trackid=sp-006&q={searchTerms}</a>"</p><p>"Search Bar"="<a href="https://www.google.com/?trackid=sp-006" target="_blank">https://www.google.com/?trackid=sp-006</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]</p><p>"Start Page"="<a href="https://www.google.com/?trackid=sp-006" target="_blank">https://www.google.com/?trackid=sp-006</a>"</p><p>"Search Page"="<a href="https://www.google.com/search?trackid=sp-006&q={searchTerms}" target="_blank">https://www.google.com/search?trackid=sp-006&q={searchTerms}</a>"</p><p>"Search Bar"="<a href="https://www.google.com/?trackid=sp-006" target="_blank">https://www.google.com/?trackid=sp-006</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]</p><p>"Start Page"="<a href="https://www.google.com/?trackid=sp-006" target="_blank">https://www.google.com/?trackid=sp-006</a>"</p><p>"Search Page"="<a href="https://www.google.com/search?trackid=sp-006&q={searchTerms}" target="_blank">https://www.google.com/search?trackid=sp-006&q={searchTerms}</a>"</p><p>"Search Bar"="<a href="https://www.google.com/?trackid=sp-006" target="_blank">https://www.google.com/?trackid=sp-006</a>"</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]</p><p>"Default_Search_URL"="<a href="http://www.safesear.ch/web/?type=20150609-155-sshome-ie-df&q={searchTerms}" target="_blank">http://www.safesear.ch/web/?type=20150609-155-sshome-ie-df&q={searchTerms}</a>"</p><p>"SearchAssistant"="<a href="http://www.safesear.ch/web/?type=20150609-155-sshome-ie-df&q={searchTerms}" target="_blank">http://www.safesear.ch/web/?type=20150609-155-sshome-ie-df&q={searchTerms}</a>"</p><p></p><p>New Values:</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]</p><p>"Search Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>"</p><p>"Search Bar"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>"</p><p>"Start Page"="<a href="https://www.google.com/?trackid=sp-006" target="_blank">https://www.google.com/?trackid=sp-006</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]</p><p>"Search Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>"</p><p>"Search Bar"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>"</p><p>"Start Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]</p><p>"Search Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>"</p><p>"Search Bar"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>"</p><p>"Start Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>"</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]</p><p>"Default_Search_URL"="<a href="http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank">http://go.microsoft.com/fwlink/?LinkId=54896</a>"</p><p>"SearchAssistant"="<a href="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" target="_blank">http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm</a>"</p><p></p><p>==== All HKCU SearchScopes ======================</p><p></p><p>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes</p><p>"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"</p><p>{012E1000-F331-11DB-8314-0800200C9A66} Google Url="<a href="http://www.google.com/search?q={searchTerms}" target="_blank">http://www.google.com/search?q={searchTerms}</a>"</p><p>{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="<a href="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" target="_blank">http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC</a>"</p><p>{AC4B9F99-A487-485D-A33D-04DB57629A8B} Unknown Url="Not_Found"</p><p>{E9410C70-B6AE-41FF-AB71-32F4B279EA5F} Google Url="<a href="https://www.google.com/search?trackid=sp-006&q={searchTerms}" target="_blank">https://www.google.com/search?trackid=sp-006&q={searchTerms}</a>"</p><p></p><p>==== Deleting CLSID Registry Keys ======================</p><p></p><p>HKEY_USERS\S-1-5-21-4272160834-3168868320-1750411223-1001\Software\Microsoft\Internet Explorer\SearchScopes\{AC4B9F99-A487-485D-A33D-04DB57629A8B} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AC4B9F99-A487-485D-A33D-04DB57629A8B} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AC4B9F99-A487-485D-A33D-04DB57629A8B} deleted successfully</p><p></p><p>==== Deleting CLSID Registry Values ======================</p><p></p><p></p><p>==== shortcuts on All Users Desktop ======================</p><p></p><p>C:\Users\Public\Desktop\Avast Internet Security.lnk - C:\Program Files\AVAST Software\Avast\avastui.exe </p><p>C:\Users\Public\Desktop\Avast SafeZone.lnk - C:\Program Files\AVAST Software\Avast\avastui.exe /sfzonebrowser</p><p>C:\Users\Public\Desktop\Battle.net.lnk - C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe </p><p>C:\Users\Public\Desktop\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe </p><p>C:\Users\Public\Desktop\Diablo III.lnk - C:\Program Files (x86)\Diablo III\Diablo III Launcher.exe </p><p>C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe </p><p>C:\Users\Public\Desktop\Hearthstone.lnk - C:\Program Files (x86)\Hearthstone\Hearthstone Beta Launcher.exe </p><p></p><p>==== shortcuts in All Users Start Menu ======================</p><p></p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Google Chrome.lnk - C:\Program Files (x86)\Fast Browser\Application\chrome.exe <a href="http://www.safesear.ch/?type=20150609-155-ch-ur" target="_blank">http://www.safesear.ch/?type=20150609-155-ch-ur</a></p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk - C:\windows\Installer\{AC76BA86-7AD7-1033-7B44-AB0000000001}\SC_Reader.ico </p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe </p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe </p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Docs.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_document</p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Drive.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe </p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Sheets.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_spreadsheet</p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Slides.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_presentation</p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone\Hearthstone.lnk - C:\Program Files (x86)\Hearthstone\Hearthstone Beta Launcher.exe </p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk - C:\Program Files (x86)\Java\jre1.8.0_45\bin\javacpl.exe -tab about</p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk - C:\Program Files (x86)\Java\jre1.8.0_45\bin\javacpl.exe -tab update</p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk - C:\Program Files (x86)\Java\jre1.8.0_45\bin\javacpl.exe </p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.lnk - </p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.lnk - </p><p></p><p>==== shortcuts in Quick Launch ======================</p><p></p><p>C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - </p><p>C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - </p><p>C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - </p><p>C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - </p><p></p><p>==== shortcuts After Repair ======================</p><p></p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Google Chrome.lnk - C:\Program Files (x86)\Fast Browser\Application\chrome.exe </p><p></p><p>==== Deleting Registry Keys ======================</p><p></p><p>HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully</p><p>HKEY_CURRENT_USER\Software\Policies\Google deleted successfully</p><p></p><p>==== Empty IE Cache ======================</p><p></p><p>C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Users\Lise Marie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Users\Lise Marie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully</p><p>C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p></p><p>==== Empty FireFox Cache ======================</p><p></p><p>C:\Users\Lise Marie\AppData\Local\Mozilla\Firefox\Profiles\br8kvdch.default\Cache emptied successfully</p><p></p><p>==== Empty Chrome Cache ======================</p><p></p><p>C:\Users\Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully</p><p></p><p>==== Empty All Flash Cache ======================</p><p></p><p>Flash Cache Emptied Successfully</p><p></p><p>==== Empty All Java Cache ======================</p><p></p><p>Java Cache cleared successfully</p><p></p><p>==== C:\zoek_backup content ======================</p><p></p><p>C:\zoek_backup (files=46 folders=17 112702901 bytes)</p><p></p><p>==== Empty Temp Folders ======================</p><p></p><p>C:\Users\ADMINI~1\AppData\Local\Temp emptied successfully</p><p>C:\Users\Default\AppData\Local\Temp emptied successfully</p><p>C:\Users\Default User\AppData\Local\Temp emptied successfully</p><p>C:\Users\Lise Marie\AppData\Local\Temp will be emptied at reboot</p><p>C:\windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot</p><p>C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully</p><p>C:\windows\Temp will be emptied at reboot</p><p></p><p>==== After Reboot ======================</p><p></p><p>==== Empty Temp Folders ======================</p><p></p><p>C:\windows\Temp successfully emptied</p><p>C:\Users\LISEMA~1\AppData\Local\Temp successfully emptied</p><p></p><p>==== Empty Recycle Bin ======================</p><p></p><p>C:\$RECYCLE.BIN successfully emptied</p><p></p><p>==== Deleting Files / Folders ======================</p><p></p><p>"C:\windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted</p><p></p><p>==== EOF on Sat 06/13/2015 at 9:50:48.61 ======================</p></blockquote><p></p>
[QUOTE="celloxsaurus, post: 397229, member: 37046"] I apologize for the delay in responding. Here is the log file you requested. edit: attempting to upload the file itself throws an error (the file is empty); here is the content of the file: Zoek.exe v5.0.0.0 Updated 04-May-2015 Tool run by Lise Marie on Fri 06/12/2015 at 21:50:16.90. Microsoft Windows 8 6.2.9200 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Lise Marie\Downloads\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 6/12/2015 9:52:22 PM Zoek.exe System Restore Point Created Successfully. ==== Empty Folders Check ====================== C:\PROGRA~2\Amazon deleted successfully C:\PROGRA~2\Errors deleted successfully C:\PROGRA~2\SafeConnect deleted successfully C:\PROGRA~2\The Weather Channel FW deleted successfully C:\PROGRA~2\COMMON~1\supportdotcom deleted successfully C:\Users\Lise Marie\AppData\Local\Component deleted successfully C:\Users\Lise Marie\AppData\Local\StormAlerts deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-4272160834-3168868320-1750411223-1001\Software\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5} deleted successfully HKEY_USERS\S-1-5-21-4272160834-3168868320-1750411223-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{814FEF07-4D9D-40C8-9721-59711B2045C1} deleted successfully HKEY_USERS\S-1-5-21-4272160834-3168868320-1750411223-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{839AB207-35B9-4D10-B707-3038D88D0EDD} deleted successfully HKEY_USERS\S-1-5-21-4272160834-3168868320-1750411223-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4E39681-15F8-4fda-B8A3-B5C98378F2F3} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{632F07F3-19A1-4d16-A23F-E6CE9486BAB5} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Registry Fix Code ====================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command] @="C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command] @="C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe" ==== Batch Command(s) Run By Tool====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~2\Amazon not found C:\PROGRA~2\Errors not found C:\PROGRA~2\SafeConnect not found C:\PROGRA~2\The Weather Channel FW not found C:\PROGRA~2\The Weather Channel deleted C:\Users\Lise Marie\AppData\Roaming\Scorch_Install.log deleted C:\PROGRA~3\eBay deleted C:\PROGRA~3\Package Cache deleted C:\Users\Lise Marie\AppData\Local\CRE deleted C:\windows\SysNative\Tasks\avastBCLRestartS-1-5-21-4272160834-3168868320-1750411223-1001 deleted C:\windows\SysNative\Tasks\avastBCLRestart_chrome.exe deleted C:\windows\SysNative\GroupPolicy\Machine deleted C:\windows\SysNative\GroupPolicy\User deleted C:\windows\SysNative\GroupPolicy\GPT.INI deleted C:\windows\Syswow64\GroupPolicy\gpt.ini deleted C:\windows\SysWow64\AI_RecycleBin deleted ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\LISEMA~1\AppData\Roaming\Mozilla\Firefox\Profiles\br8kvdch.default user_pref("browser.startup.homepage", "[URL]https://www.google.com/?trackid=sp-006[/URL]"); user_pref("browser.search.defaulturl", "[URL]https://www.google.com/search/?trackid=sp-006[/URL]"); user_pref("browser.search.defaultengine", "Google (avast)"); user_pref("browser.search.defaultenginename", "Google (avast)"); user_pref("browser.search.selectedEngine", "Google (avast)"); user_pref("keyword.URL", "[URL]https://www.google.com/search/?trackid=sp-006[/URL]"); user_pref("keyword.url", "[URL]http://www.safesear.ch/web/?type=ss-ff-kw&q=[/URL]"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "[email]wrc@avast.com[/email]"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [02/21/2015 03:24 PM] ==== Firefox Extensions ====================== AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Lise Marie\AppData\Roaming\Mozilla\Firefox\Profiles\br8kvdch.default 08ACECEB47FAF053C468D8AFE44709AD - C:\Users\Lise Marie\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll - Google Update 49D429EBF5305FC9ADD7545B7C914333 - C:\Users\Lise Marie\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll - Google Talk Plugin 6BEAD7859E8A087BE04556AB5A78855C - C:\Users\Lise Marie\AppData\Roaming\Mozilla\plugins\npo1d.dll - Google Talk Plugin Video Renderer C899B98999270821EDFFA56044DE2377 - C:\Users\Lise Marie\AppData\Roaming\raidcall\plugins\nprcplugin.dll - Raidcall plugin FEF9ECECFA177AEC0F7564A08394D2C8 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll - RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit) 0ABF093757E9C827E30EC652868E5FAC - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll - RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit) 06E140A567B8DC7900173197FD059EE5 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll - RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit) 558270B968CB82196CB8D045D13B0FF6 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll - RealDownloader Plugin ==== Chromium Look ====================== Google Chrome Version: 43.0.2357.124 HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[12/01/2014 01:33 AM] idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[11/29/2012 09:35 PM] Avast Online Security - Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki Chrome Hotword Shared Module - Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg ==== Chromium Startpages ====================== C:\Users\Lise Marie\AppData\Local\Fast Browser\User Data\Default\Preferences "homepage": "[URL]http://www.safesear.ch/?type=20150609[/URL]", "startup_urls": [ "[URL]http://www.safesear.ch/?type=20150609[/URL]" ], "urls_to_restore_on_startup": [ "[URL]http://www.safesear.ch/?type=20150609[/URL]" ] C:\Users\Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Preferences imaahmaaome":"E7BA8F30FD44E67901DE959C7A9CF4F576AD3A6DAB3FD14760ACB4DE9F1B84D8","nmmhkkegccagdldgiimedpiccmgmieda":"58B6BDE35EA09B8B3AA6CD267D926B7C6E8E72D53907BC34CA827D323C32D008","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"29F4C6BE6DB6D4F04B922CD88F77D6665F062E525CA7EBEC654710C5FA7D1602"}},"google":{"services":{"last_username":"873143D4F9AC99735C4AA2DE5752A36358D823698C23531FBEAF78653C2A6420","username":"AE5970C01B69F0636822443E93C8D011415E9BB340A26F608C19F104D827578E"}},"homepage":"3042A70A480F6F993D0F2714AADE08D68F4A85A195CBD151549D347C291FF33D","homepage_is_newtabpage":"F6BD04CEC1E1FBECB3E1B66497AFBC51A7E2613776ABB452C4F9D4502AEEC1A4","pinned_tabs":"21C7811A6CA1296A533EB7401FAA4D22841B769E736E4028C882B335E4CDE857","prefs":{"preference_reset_time":"A922F20D6CF2E83237784DAF430E1A142181ECED93D2647F81118D2C3BB8C3CA"},"profile":{"reset_prompt_memento":"79947232471C57AAF3BE0C4261C554C4C3F2F87539B47349D26526DF4A91595E"},"safebrowsing":{"incidents_sent":"E703B6B25254C0366E49DD7D5CAF85537446AC2595A61993C96B330E1D09468C"},"search_provider_overrides":"39AC5543DC9FF1BD42123B1E784F31FB3092D3F963DE0EEE9D68F1FF26563BFE","session":{"restore_on_startup":"CAB0A1C0598D64E57732FFC3FF391C512787D181A7BE07E0703A43769B08062D","startup_urls":"3BABF93F5300FD9E131C2EFF113091EEEEDDB468A31D8AB716390AAE1BA19974"},"software_reporter":{"prompt_reason":"32748ACDD47BD4841A6698B1E78174F5547E12B0C518D354EA86C9D528C97C33","prompt_seed":"FA66EB38B726A33AF523D8927B4CD55C4910ED3B4C21EEBA2D73D89675319B7F","prompt_version":"0F2886C329593BDFB58961F50D05B802F740678E37BFBB6B2E8FA0535A200888"},"sync":{"remaining_rollback_tries":"C566C66369E0276D3351166E703C512B4CF59B330DB1E142DD1842E9A9941FBB"}},"super_mac":"34F8FCA197626FC15B77B411D735580D142F91D7553D9963F08D04F6A322C9E1"},"session":{"restore_on_startup":4,"startup_urls":["[URL]http://www.google.com/[/URL]","[URL]http://www.msn.com/?pc=AV01[/URL]"]},"software_reporter":{"prompt_reason":0,"prompt_seed":"20150601","prompt_version":"3.21.0"},"sync":{"remaining_rollback_tries":0}} ==== Chromium Fix ====================== C:\Users\Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage deleted successfully C:\Users\Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully C:\Users\Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_services2.capitalone.com_0.localstorage deleted successfully C:\Users\Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_services2.capitalone.com_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="[URL]https://www.google.com/?trackid=sp-006[/URL]" "Search Page"="[URL]https://www.google.com/search?trackid=sp-006&q={searchTerms}[/URL]" "Search Bar"="[URL]https://www.google.com/?trackid=sp-006[/URL]" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="[URL]https://www.google.com/?trackid=sp-006[/URL]" "Search Page"="[URL]https://www.google.com/search?trackid=sp-006&q={searchTerms}[/URL]" "Search Bar"="[URL]https://www.google.com/?trackid=sp-006[/URL]" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Start Page"="[URL]https://www.google.com/?trackid=sp-006[/URL]" "Search Page"="[URL]https://www.google.com/search?trackid=sp-006&q={searchTerms}[/URL]" "Search Bar"="[URL]https://www.google.com/?trackid=sp-006[/URL]" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="[URL]http://www.safesear.ch/web/?type=20150609-155-sshome-ie-df&q={searchTerms}[/URL]" "SearchAssistant"="[URL]http://www.safesear.ch/web/?type=20150609-155-sshome-ie-df&q={searchTerms}[/URL]" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="[URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]" "Search Bar"="[URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]" "Start Page"="[URL]https://www.google.com/?trackid=sp-006[/URL]" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Search Page"="[URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]" "Search Bar"="[URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]" "Start Page"="[URL]http://go.microsoft.com/fwlink/?LinkId=69157[/URL]" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Search Page"="[URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]" "Search Bar"="[URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]" "Start Page"="[URL]http://go.microsoft.com/fwlink/?LinkId=69157[/URL]" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="[URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]" "SearchAssistant"="[URL]http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm[/URL]" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="[URL]http://www.google.com/search?q={searchTerms}[/URL]" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="[URL]http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC[/URL]" {AC4B9F99-A487-485D-A33D-04DB57629A8B} Unknown Url="Not_Found" {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} Google Url="[URL]https://www.google.com/search?trackid=sp-006&q={searchTerms}[/URL]" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-4272160834-3168868320-1750411223-1001\Software\Microsoft\Internet Explorer\SearchScopes\{AC4B9F99-A487-485D-A33D-04DB57629A8B} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AC4B9F99-A487-485D-A33D-04DB57629A8B} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AC4B9F99-A487-485D-A33D-04DB57629A8B} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== shortcuts on All Users Desktop ====================== C:\Users\Public\Desktop\Avast Internet Security.lnk - C:\Program Files\AVAST Software\Avast\avastui.exe C:\Users\Public\Desktop\Avast SafeZone.lnk - C:\Program Files\AVAST Software\Avast\avastui.exe /sfzonebrowser C:\Users\Public\Desktop\Battle.net.lnk - C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe C:\Users\Public\Desktop\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe C:\Users\Public\Desktop\Diablo III.lnk - C:\Program Files (x86)\Diablo III\Diablo III Launcher.exe C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Users\Public\Desktop\Hearthstone.lnk - C:\Program Files (x86)\Hearthstone\Hearthstone Beta Launcher.exe ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Google Chrome.lnk - C:\Program Files (x86)\Fast Browser\Application\chrome.exe [URL]http://www.safesear.ch/?type=20150609-155-ch-ur[/URL] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk - C:\windows\Installer\{AC76BA86-7AD7-1033-7B44-AB0000000001}\SC_Reader.ico C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Docs.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_document C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Drive.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Sheets.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_spreadsheet C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Slides.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_presentation C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone\Hearthstone.lnk - C:\Program Files (x86)\Hearthstone\Hearthstone Beta Launcher.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk - C:\Program Files (x86)\Java\jre1.8.0_45\bin\javacpl.exe -tab about C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk - C:\Program Files (x86)\Java\jre1.8.0_45\bin\javacpl.exe -tab update C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk - C:\Program Files (x86)\Java\jre1.8.0_45\bin\javacpl.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.lnk - ==== shortcuts in Quick Launch ====================== C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - ==== shortcuts After Repair ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Google Chrome.lnk - C:\Program Files (x86)\Fast Browser\Application\chrome.exe ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully HKEY_CURRENT_USER\Software\Policies\Google deleted successfully ==== Empty IE Cache ====================== C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Lise Marie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Lise Marie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Lise Marie\AppData\Local\Mozilla\Firefox\Profiles\br8kvdch.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Lise Marie\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=46 folders=17 112702901 bytes) ==== Empty Temp Folders ====================== C:\Users\ADMINI~1\AppData\Local\Temp emptied successfully C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Lise Marie\AppData\Local\Temp will be emptied at reboot C:\windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\windows\Temp successfully emptied C:\Users\LISEMA~1\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted ==== EOF on Sat 06/13/2015 at 9:50:48.61 ====================== [/QUOTE]
Insert quotes…
Verification
Post reply
Top