Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
GoSave - need help with removal
Message
<blockquote data-quote="garchie" data-source="post: 269873" data-attributes="member: 28517"><p>Zoek.exe v5.0.0.0 Updated 27-09-2014</p><p>Tool run by Aaryn on Tue 30/09/2014 at 9:32:09.55.</p><p>Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64</p><p>Running in: Normal Mode Internet Access Detected</p><p>Launched: C:\Users\Aaryn\Downloads\zoek.exe [Scan all users] [Script inserted] </p><p></p><p>==== System Restore Info ======================</p><p></p><p>30/09/2014 9:35:34 a.m. Zoek.exe System Restore Point Created Succesfully.</p><p></p><p>==== Deleting CLSID Registry Keys ======================</p><p></p><p></p><p>==== Deleting CLSID Registry Values ======================</p><p></p><p></p><p>==== Deleting Services ======================</p><p></p><p></p><p>==== FireFox Fix ======================</p><p></p><p>ProfilePath: C:\Users\Aaryn\AppData\Roaming\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765</p><p></p><p>user.js not found</p><p>---- Lines WebSearch removed from prefs.js ----</p><p>user_pref("browser.search.defaultenginename", "WebSearch");</p><p>user_pref("browser.search.defaultenginename,S", "WebSearch");</p><p>user_pref("browser.search.order.1", "WebSearch");</p><p>user_pref("browser.search.order.1,S", "WebSearch");</p><p>user_pref("browser.search.selectedEngine", "WebSearch");</p><p>user_pref("browser.search.selectedEngine,S", "WebSearch");</p><p>---- FireFox user.js and prefs.js backups ---- </p><p></p><p>prefs_20143009_0951_.backup</p><p></p><p>==== Batch Command(s) Run By Tool======================</p><p></p><p></p><p>==== Deleting Files \ Folders ======================</p><p></p><p>C:\PROGRA~3\{93E26451-CD9A-43A5-A2FA-C42392EA4001} deleted</p><p>C:\PROGRA~3\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E} deleted</p><p>C:\PROGRA~3\{DDB686B4-4F6B-46EB-B3F0-E73DAF04B8F0} deleted</p><p>C:\PROGRA~3\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} deleted</p><p>C:\PROGRA~3\4c3c5f6b1d53a6bd deleted</p><p>C:\PROGRA~3\DivX deleted</p><p>C:\Users\Aaryn\.android deleted</p><p>C:\PROGRA~2\Wondershare deleted</p><p>C:\install.exe deleted</p><p>C:\Users\Aaryn\AppData\Roaming\SkypEmoticons deleted</p><p>C:\Users\Aaryn\AppData\Roaming\ParetoLogic deleted</p><p>C:\Users\Aaryn\AppData\Roaming\DriverCure deleted</p><p>C:\PROGRA~3\Wondershare Video Converter Ultimate deleted</p><p>C:\PROGRA~3\ParetoLogic deleted</p><p>C:\PROGRA~3\Uniblue\DriverScanner deleted</p><p>C:\PROGRA~3\Uniblue deleted</p><p>C:\PROGRA~3\InstallMate deleted</p><p>C:\PROGRA~3\Package Cache deleted</p><p>C:\Users\Aaryn\AppData\Local\Wondershare deleted</p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted</p><p>C:\Windows\SysNative\roboot64.exe deleted</p><p>C:\Users\Aaryn\Downloads\BabylonClientRemovalTool.exe deleted</p><p>C:\windows\SysNative\tasks\RunAsStdUser Task deleted</p><p>C:\Users\Aaryn\AppData\Roaming\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765\jetpack deleted</p><p>C:\Users\Aaryn\AppData\Roaming\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765\extensions\staged deleted</p><p>C:\Users\Aaryn\AppData\Roaming\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765\extensions\<a href="mailto:1uoN@zAw.com">1uoN@zAw.com</a> deleted</p><p>C:\Users\Aaryn\AppData\Roaming\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765\extensions\<a href="mailto:pQDkpWxP3@o.edu">pQDkpWxP3@o.edu</a> deleted</p><p>"C:\PROGRA~2\COMMON~1\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll" deleted</p><p>"C:\PROGRA~2\COMMON~1\Wondershare\Wondershare Helper Compact\CBSProducstInfo.dll" deleted</p><p>"C:\PROGRA~2\COMMON~1\Wondershare\Wondershare Helper Compact\DAQExp.dll" deleted</p><p>"C:\PROGRA~2\COMMON~1\Wondershare\Wondershare Helper Compact\WSHelper.exe" deleted</p><p>"C:\PROGRA~2\COMMON~1\Wondershare" deleted</p><p>"C:\PROGRA~2\COMMON~1\Wondershare\Wondershare Helper Compact" deleted</p><p></p><p>==== Firefox Extensions Registry ======================</p><p></p><p>[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]</p><p>"{e4f94d1e-2f53-401e-8885-681602c0ddd8}"="C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi" [04/04/2014 11:36 p.m.]</p><p></p><p>==== Firefox Extensions ======================</p><p></p><p>ProfilePath: C:\Users\Aaryn\AppData\Roaming\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765</p><p>- Undetermined - C:\ProgramData\Wondershare\Video Converter Ultimate\<a href="mailto:WSVCU@Wondershare.com">WSVCU@Wondershare.com</a></p><p>- Flash Video Downloader - YouTube Full HD Download - %ProfilePath%\extensions\<a href="mailto:artur.dubovoy@gmail.com">artur.dubovoy@gmail.com</a></p><p>- DownloadHelper - %ProfilePath%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}</p><p>- AVG PrivacyFix - %ProfilePath%\extensions\{7CA9CF31-1C73-46CD-8377-85AB71EA771F}.xpi</p><p>- SoundCloud Downloader - Technowise - %ProfilePath%\extensions\{c8d3bc80-0810-4d21-a2c2-be5f2b2832ac}.xpi</p><p>- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi</p><p></p><p>AppDir: C:\Program Files (x86)\Mozilla Firefox</p><p>- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}</p><p>- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi</p><p></p><p>==== Firefox Plugins ======================</p><p></p><p>Profilepath: C:\Users\Aaryn\AppData\Roaming\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765</p><p>DFC9460CC37E5C414DC4680B10C19E7A - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll - Shockwave Flash</p><p>853A6F93105790D4DC4D30CC92B19E11 - C:\Users\Aaryn\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player</p><p></p><p></p><p>==== Chromium Look ======================</p><p></p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions</p><p>bopakagnckmlgajfccecajhnimjiiedh - No path found[]</p><p>lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[03/01/2014 01:32 a.m.]</p><p></p><p>GoSSave - Aaryn\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - Aaryn\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - Aaryn\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - Aaryn\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - Aaryn\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Google Voice Search Hotword (Beta) - Aaryn\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn</p><p>Google Wallet - Aaryn\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda</p><p>GoSSave - Aaryn\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - Aaryn\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - Aaryn\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - Aaryn\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - Administrator\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - Administrator\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - Guest\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - Guest\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p>GoSSave - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik</p><p>Saving Flash - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle</p><p></p><p>==== Chromium Startpages ======================</p><p></p><p>C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Preferences</p><p>"homepage": "<a href="http://websearch.flyandsearch.info/?pid=724&r=2014/09/19&hid=4352121981955475165&lg=EN&cc=NZ" target="_blank">http://websearch.flyandsearch.info/?pid=724&r=2014/09/19&hid=4352121981955475165&lg=EN&cc=NZ</a>",</p><p>"startup_urls": [ "<a href="http://websearch.flyandsearch.info/?pid=724&r=2014/09/19&hid=4352121981955475165&lg=EN&cc=NZ" target="_blank">http://websearch.flyandsearch.info/?pid=724&r=2014/09/19&hid=4352121981955475165&lg=EN&cc=NZ</a>" ],</p><p></p><p></p><p>==== Chromium Fix ======================</p><p></p><p>C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_<a href="http://www.superfish.com_0.localstorage" target="_blank">www.superfish.com_0.localstorage</a> deleted successfully</p><p>C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_<a href="http://www.superfish.com_0.localstorage-journal" target="_blank">www.superfish.com_0.localstorage-journal</a> deleted successfully</p><p>C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_<a href="http://www.superfish.com_0.localstorage" target="_blank">www.superfish.com_0.localstorage</a> deleted successfully</p><p>C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_<a href="http://www.superfish.com_0.localstorage-journal" target="_blank">www.superfish.com_0.localstorage-journal</a> deleted successfully</p><p>C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_free-windows-cleanup-tool.en.softonic.com_0.localstorage deleted successfully</p><p>C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_free-windows-cleanup-tool.en.softonic.com_0.localstorage-journal deleted successfully</p><p>C:\Users\Aaryn\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\Aaryn\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\Aaryn\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\Aaryn\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully</p><p>C:\Users\Aaryn\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\Aaryn\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\Aaryn\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\Aaryn\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p>C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully</p><p></p><p>==== Set IE to Default ======================</p><p></p><p>Old Values:</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]</p><p></p><p>New Values:</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]</p><p>"Start Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>"</p><p></p><p>==== All HKCU SearchScopes ======================</p><p></p><p>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes</p><p>"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"</p><p>{012E1000-F331-11DB-8314-0800200C9A66} Google Url="<a href="http://www.google.com/search?q={searchTerms}" target="_blank">http://www.google.com/search?q={searchTerms}</a>"</p><p>{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="<a href="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02" target="_blank">http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02</a>"</p><p>{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="<a href="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGHP_en" target="_blank">http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGHP_en</a>"</p><p></p><p>==== Deleting Registry Keys ======================</p><p></p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\5be60477-93f0-455a-93f4-735abcdf0a3a deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh deleted successfully</p><p></p><p>==== Empty IE Cache ======================</p><p></p><p>C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Users\Aaryn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Users\Aaryn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully</p><p>C:\Users\Aaryn\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Users\Aaryn\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Users\Aaryn\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p></p><p>==== Empty FireFox Cache ======================</p><p></p><p>C:\Users\Aaryn\AppData\Local\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765\Cache will be emptied at reboot</p><p></p><p>==== Empty Chrome Cache ======================</p><p></p><p>C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully</p><p></p><p>==== Empty All Flash Cache ======================</p><p></p><p>Flash Cache is not empty, a reboot is needed</p><p></p><p>==== Empty All Java Cache ======================</p><p></p><p>Java Cache cleared successfully</p><p></p><p>==== C:\zoek_backup content ======================</p><p></p><p>C:\zoek_backup (files=306 folders=151 37834568 bytes)</p><p></p><p>==== Empty Temp Folders ======================</p><p></p><p>C:\Users\Aaryn\AppData\Local\Temp will be emptied at reboot</p><p>C:\Users\Default\AppData\Local\Temp emptied successfully</p><p>C:\Users\Default User\AppData\Local\Temp emptied successfully</p><p>C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot</p><p>C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully</p><p>C:\Windows\Temp will be emptied at reboot</p><p></p><p>==== After Reboot ======================</p><p></p><p>==== Empty Temp Folders ======================</p><p></p><p>C:\Windows\Temp successfully emptied</p><p>C:\Users\Aaryn\AppData\Local\Temp successfully emptied</p><p></p><p>==== Empty Recycle Bin ======================</p><p></p><p>C:\$RECYCLE.BIN successfully emptied</p><p></p><p>==== Deleting Files / Folders ======================</p><p></p><p>"C:\Users\Aaryn\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5CET3JVC\fbstatic-a.akamaihd.net" not found</p><p>"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted</p><p></p><p>==== EOF on Tue 30/09/2014 at 10:01:57.00 ======================</p></blockquote><p></p>
[QUOTE="garchie, post: 269873, member: 28517"] Zoek.exe v5.0.0.0 Updated 27-09-2014 Tool run by Aaryn on Tue 30/09/2014 at 9:32:09.55. Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Aaryn\Downloads\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 30/09/2014 9:35:34 a.m. Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== FireFox Fix ====================== ProfilePath: C:\Users\Aaryn\AppData\Roaming\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765 user.js not found ---- Lines WebSearch removed from prefs.js ---- user_pref("browser.search.defaultenginename", "WebSearch"); user_pref("browser.search.defaultenginename,S", "WebSearch"); user_pref("browser.search.order.1", "WebSearch"); user_pref("browser.search.order.1,S", "WebSearch"); user_pref("browser.search.selectedEngine", "WebSearch"); user_pref("browser.search.selectedEngine,S", "WebSearch"); ---- FireFox user.js and prefs.js backups ---- prefs_20143009_0951_.backup ==== Batch Command(s) Run By Tool====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~3\{93E26451-CD9A-43A5-A2FA-C42392EA4001} deleted C:\PROGRA~3\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E} deleted C:\PROGRA~3\{DDB686B4-4F6B-46EB-B3F0-E73DAF04B8F0} deleted C:\PROGRA~3\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} deleted C:\PROGRA~3\4c3c5f6b1d53a6bd deleted C:\PROGRA~3\DivX deleted C:\Users\Aaryn\.android deleted C:\PROGRA~2\Wondershare deleted C:\install.exe deleted C:\Users\Aaryn\AppData\Roaming\SkypEmoticons deleted C:\Users\Aaryn\AppData\Roaming\ParetoLogic deleted C:\Users\Aaryn\AppData\Roaming\DriverCure deleted C:\PROGRA~3\Wondershare Video Converter Ultimate deleted C:\PROGRA~3\ParetoLogic deleted C:\PROGRA~3\Uniblue\DriverScanner deleted C:\PROGRA~3\Uniblue deleted C:\PROGRA~3\InstallMate deleted C:\PROGRA~3\Package Cache deleted C:\Users\Aaryn\AppData\Local\Wondershare deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted C:\Windows\SysNative\roboot64.exe deleted C:\Users\Aaryn\Downloads\BabylonClientRemovalTool.exe deleted C:\windows\SysNative\tasks\RunAsStdUser Task deleted C:\Users\Aaryn\AppData\Roaming\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765\jetpack deleted C:\Users\Aaryn\AppData\Roaming\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765\extensions\staged deleted C:\Users\Aaryn\AppData\Roaming\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765\extensions\[email]1uoN@zAw.com[/email] deleted C:\Users\Aaryn\AppData\Roaming\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765\extensions\[email]pQDkpWxP3@o.edu[/email] deleted "C:\PROGRA~2\COMMON~1\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll" deleted "C:\PROGRA~2\COMMON~1\Wondershare\Wondershare Helper Compact\CBSProducstInfo.dll" deleted "C:\PROGRA~2\COMMON~1\Wondershare\Wondershare Helper Compact\DAQExp.dll" deleted "C:\PROGRA~2\COMMON~1\Wondershare\Wondershare Helper Compact\WSHelper.exe" deleted "C:\PROGRA~2\COMMON~1\Wondershare" deleted "C:\PROGRA~2\COMMON~1\Wondershare\Wondershare Helper Compact" deleted ==== Firefox Extensions Registry ====================== [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "{e4f94d1e-2f53-401e-8885-681602c0ddd8}"="C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi" [04/04/2014 11:36 p.m.] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Aaryn\AppData\Roaming\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765 - Undetermined - C:\ProgramData\Wondershare\Video Converter Ultimate\[email]WSVCU@Wondershare.com[/email] - Flash Video Downloader - YouTube Full HD Download - %ProfilePath%\extensions\[email]artur.dubovoy@gmail.com[/email] - DownloadHelper - %ProfilePath%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} - AVG PrivacyFix - %ProfilePath%\extensions\{7CA9CF31-1C73-46CD-8377-85AB71EA771F}.xpi - SoundCloud Downloader - Technowise - %ProfilePath%\extensions\{c8d3bc80-0810-4d21-a2c2-be5f2b2832ac}.xpi - Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} - Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi ==== Firefox Plugins ====================== Profilepath: C:\Users\Aaryn\AppData\Roaming\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765 DFC9460CC37E5C414DC4680B10C19E7A - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll - Shockwave Flash 853A6F93105790D4DC4D30CC92B19E11 - C:\Users\Aaryn\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions bopakagnckmlgajfccecajhnimjiiedh - No path found[] lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[03/01/2014 01:32 a.m.] GoSSave - Aaryn\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - Aaryn\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - Aaryn\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - Aaryn\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - Aaryn\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Google Voice Search Hotword (Beta) - Aaryn\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn Google Wallet - Aaryn\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda GoSSave - Aaryn\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - Aaryn\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - Aaryn\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - Aaryn\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - Administrator\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - Administrator\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - Guest\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - Guest\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle GoSSave - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik Saving Flash - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle ==== Chromium Startpages ====================== C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Preferences "homepage": "[url]http://websearch.flyandsearch.info/?pid=724&r=2014/09/19&hid=4352121981955475165&lg=EN&cc=NZ[/url]", "startup_urls": [ "[url]http://websearch.flyandsearch.info/?pid=724&r=2014/09/19&hid=4352121981955475165&lg=EN&cc=NZ[/url]" ], ==== Chromium Fix ====================== C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_[url="http://www.superfish.com_0.localstorage"]www.superfish.com_0.localstorage[/url] deleted successfully C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_[url="http://www.superfish.com_0.localstorage-journal"]www.superfish.com_0.localstorage-journal[/url] deleted successfully C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_[url="http://www.superfish.com_0.localstorage"]www.superfish.com_0.localstorage[/url] deleted successfully C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_[url="http://www.superfish.com_0.localstorage-journal"]www.superfish.com_0.localstorage-journal[/url] deleted successfully C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_free-windows-cleanup-tool.en.softonic.com_0.localstorage deleted successfully C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_free-windows-cleanup-tool.en.softonic.com_0.localstorage-journal deleted successfully C:\Users\Aaryn\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\Aaryn\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\Aaryn\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\Aaryn\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\agidjkjhbfmjnpdhhddmnddemfbbdoik deleted successfully C:\Users\Aaryn\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\Aaryn\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\Aaryn\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\Aaryn\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\Guest\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\boidnimkebefpfgbeekbjoponilnomle deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="[url]http://go.microsoft.com/fwlink/?LinkId=69157[/url]" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="[url]http://www.google.com/search?q={searchTerms}[/url]" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="[url]http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02[/url]" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="[url]http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGHP_en[/url]" ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\5be60477-93f0-455a-93f4-735abcdf0a3a deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Aaryn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Aaryn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Aaryn\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Aaryn\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Aaryn\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Aaryn\AppData\Local\Mozilla\Firefox\Profiles\k4h0svi1.default-1379193291765\Cache will be emptied at reboot ==== Empty Chrome Cache ====================== C:\Users\Aaryn\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache is not empty, a reboot is needed ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=306 folders=151 37834568 bytes) ==== Empty Temp Folders ====================== C:\Users\Aaryn\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Aaryn\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\Aaryn\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5CET3JVC\fbstatic-a.akamaihd.net" not found "C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted ==== EOF on Tue 30/09/2014 at 10:01:57.00 ====================== [/QUOTE]
Insert quotes…
Verification
Post reply
Top