Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Yes I know you've heard it before! GoSave hell
Message
<blockquote data-quote="DawnMohrbacher" data-source="post: 295136" data-attributes="member: 30421"><p>Any help would of course be so appreciated. Then I will follow your directions on protecting the computer more carefully! </p><p></p><p>Zoek.exe v5.0.0.0 Updated 06-November-2014</p><p>Tool run by Owner on Sat 11/08/2014 at 13:41:40.21.</p><p>Microsoft Windows 8.1 6.3.9600 x64</p><p>Running in: Normal Mode Internet Access Detected</p><p>Launched: C:\Users\Owner\Downloads\zoek.exe [Scan all users] [Script inserted] </p><p></p><p>==== System Restore Info ======================</p><p></p><p>11/8/2014 1:44:34 PM Zoek.exe System Restore Point Created Succesfully.</p><p></p><p>==== Deleting CLSID Registry Keys ======================</p><p></p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully</p><p></p><p>==== Deleting CLSID Registry Values ======================</p><p></p><p></p><p>==== Deleting Services ======================</p><p></p><p></p><p>==== Batch Command(s) Run By Tool======================</p><p></p><p></p><p>==== Deleting Files \ Folders ======================</p><p></p><p>C:\PROGRA~2\YoouuttubbeAdBlocke deleted</p><p>C:\ProgramData\YoouuttubbeAdBlocke deleted</p><p>C:\ProgramData\GoSSave deleted</p><p>C:\PROGRA~2\PrriceoCihhoP deleted</p><p>C:\ProgramData\PrriceoCihhoP deleted</p><p>C:\ProgramData\BestSaveForYou deleted</p><p>C:\Users\Owner\AppData\LocalLow\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted</p><p>C:\Users\Owner\AppData\LocalLow\{44925416-93EF-F42F-5775-D62213216CAF} deleted</p><p>C:\Users\Owner\AppData\LocalLow\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted</p><p>C:\Users\Owner\AppData\Local\Packages\windows_ie_ac_001\AC\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted</p><p>C:\Users\Owner\AppData\Local\Packages\windows_ie_ac_001\AC\{44925416-93EF-F42F-5775-D62213216CAF} deleted</p><p>C:\Users\Owner\AppData\Local\Packages\windows_ie_ac_001\AC\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted</p><p>C:\PROGRA~3\29becdccc39fb05b deleted</p><p>C:\PROGRA~3\JoniiiCoupOn deleted</p><p>C:\PROGRA~3\NaEWSaver deleted</p><p>C:\PROGRA~3\SaveClicker deleted</p><p>C:\PROGRA~2\SaveClicker deleted</p><p>C:\PROGRA~2\Supporter deleted</p><p>C:\PROGRA~2\Browsersafeguard deleted</p><p>C:\PROGRA~2\SearchProtect deleted</p><p>C:\PROGRA~2\Yahoo! deleted</p><p>C:\PROGRA~2\Consumer Input deleted</p><p>C:\PROGRA~2\GS_Booster deleted</p><p>C:\Users\Owner\AppData\Roaming\GetRightToGo deleted</p><p>C:\PROGRA~3\Yahoo! deleted</p><p>C:\PROGRA~3\PriceCHop deleted</p><p>C:\PROGRA~3\PC Optimizer Pro deleted</p><p>C:\Users\Owner\AppData\Local\SearchProtect deleted</p><p>C:\Users\Owner\AppData\Local\visi_coupon deleted</p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services deleted</p><p>C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted</p><p>C:\Users\Owner\AppData\LocalLow\YahooCouponAddOn deleted</p><p>C:\windows\SysNative\tasks\ConsumerInputUpdateTaskMachineCore deleted</p><p>C:\windows\SysNative\tasks\ConsumerInputUpdateTaskMachineUA deleted</p><p>C:\WINDOWS\tasks\ConsumerInputUpdateTaskMachineCore.job deleted</p><p>C:\WINDOWS\tasks\ConsumerInputUpdateTaskMachineUA.job deleted</p><p>C:\windows\SysNative\Tasks\BrowserSafeguard Update Task deleted</p><p>C:\WINDOWS\tasks\GS_Booster-S-576482620.job deleted</p><p>C:\windows\SysNative\tasks\GS_Booster-S-576482620 deleted</p><p>C:\WINDOWS\SysNative\config\systemprofile\Searches deleted</p><p>C:\windows\SysNative\GroupPolicy\Machine deleted</p><p>C:\windows\SysNative\GroupPolicy\User deleted</p><p>C:\windows\SysNative\GroupPolicy\GPT.INI deleted</p><p>C:\WINDOWS\Syswow64\GroupPolicy\gpt.ini deleted</p><p>"C:\PROGRA~3\Trusted Publisher\GS_Booster\GS_Booster.exe" deleted</p><p>"C:\PROGRA~3\Trusted Publisher" not deleted</p><p>"C:\PROGRA~3\Trusted Publisher\GS_Booster" not deleted</p><p></p><p>==== Fake Chromium Profiles Check ======================</p><p></p><p>Fake profile C:\Users\Administrator\AppData\Local\Torch deleted</p><p>Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome deleted</p><p>Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome SxS deleted</p><p>Fake profile C:\Users\Administrator\AppData\Local\Comodo\Dragon deleted</p><p>Fake profile C:\Users\Administrator\AppData\Local\Chromatic Browser deleted</p><p>Fake profile C:\Users\Guest\AppData\Local\Torch deleted</p><p>Fake profile C:\Users\Guest\AppData\Local\Google\Chrome deleted</p><p>Fake profile C:\Users\Guest\AppData\Local\Google\Chrome SxS deleted</p><p>Fake profile C:\Users\Guest\AppData\Local\Comodo\Dragon deleted</p><p>Fake profile C:\Users\Guest\AppData\Local\Chromatic Browser deleted</p><p>Fake profile C:\Users\HomeGroupUser$\AppData\Local\Torch deleted</p><p>Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome deleted</p><p>Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS deleted</p><p>Fake profile C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon deleted</p><p>Fake profile C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser deleted</p><p>Fake profile C:\Users\Owner\AppData\Local\Torch deleted</p><p>Fake profile C:\Users\Owner\AppData\Local\Google\Chrome SxS deleted</p><p>Fake profile C:\Users\Owner\AppData\Local\Comodo\Dragon deleted</p><p>Fake profile C:\Users\Owner\AppData\Local\Chromatic Browser deleted</p><p></p><p>==== Chromium Look ======================</p><p></p><p>Google Voice Search Hotword (Beta) - Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn</p><p>PriceCHop - Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\bonfmkhdhmcnfkhhjjdjgnnekiafklhk</p><p></p><p>==== Chromium Fix ======================</p><p></p><p>C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_<a href="http://www.superfish.com_0.localstorage" target="_blank">www.superfish.com_0.localstorage</a> deleted successfully</p><p>C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_<a href="http://www.superfish.com_0.localstorage-journal" target="_blank">www.superfish.com_0.localstorage-journal</a> deleted successfully</p><p>C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_<a href="http://www.superfish.com_0.localstorage" target="_blank">www.superfish.com_0.localstorage</a> deleted successfully</p><p>C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_<a href="http://www.superfish.com_0.localstorage-journal" target="_blank">www.superfish.com_0.localstorage-journal</a> deleted successfully</p><p>C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\bonfmkhdhmcnfkhhjjdjgnnekiafklhk deleted successfully</p><p></p><p>==== Set IE to Default ======================</p><p></p><p>Old Values:</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]</p><p>"Start Page"="<a href="http://www.google.com/" target="_blank">http://www.google.com/</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]</p><p>"Start Page"="<a href="http://websearch.calcitapp.info/" target="_blank">http://websearch.calcitapp.info/</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]</p><p>"Start Page"="<a href="http://websearch.calcitapp.info/" target="_blank">http://websearch.calcitapp.info/</a>"</p><p></p><p>New Values:</p><p>[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]</p><p>"Start Page"="<a href="http://www.google.com/" target="_blank">http://www.google.com/</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]</p><p>"Start Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>"</p><p>[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]</p><p>"Start Page"="<a href="http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank">http://go.microsoft.com/fwlink/?LinkId=69157</a>"</p><p></p><p>==== All HKCU SearchScopes ======================</p><p></p><p>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes</p><p>"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"</p><p>{012E1000-F331-11DB-8314-0800200C9A66} Google Url="<a href="http://www.google.com/search?q={searchTerms}" target="_blank">http://www.google.com/search?q={searchTerms}</a>"</p><p>{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="<a href="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02" target="_blank">http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02</a>"</p><p>{06C03F00-CA98-417A-B361-24876253224C} Unknown Url="Not_Found"</p><p>{2fa28606-de77-4029-af96-b231e3b8f827} Unknown Url="Not_Found"</p><p>{b7fca997-d0fb-4fe0-8afd-255e89cf9671} Unknown Url="Not_Found"</p><p>{D944BB61-2E34-4DBF-A683-47E505C587DC} eBay Url="<a href="http://rover.ebay.com/rover/1/711-154371-11896-2/4" target="_blank">http://rover.ebay.com/rover/1/711-154371-11896-2/4</a>"</p><p></p><p>==== Deleting CLSID Registry Keys ======================</p><p></p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E16E8A02-5F7D-407E-B1DB-23A301DB5580} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E16E8A02-5F7D-407E-B1DB-23A301DB5580} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Internet Explorer\SearchScopes\{06C03F00-CA98-417A-B361-24876253224C} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} deleted successfully</p><p>HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{E16E8A02-5F7D-407E-B1DB-23A301DB5580} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{E16E8A02-5F7D-407E-B1DB-23A301DB5580} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E16E8A02-5F7D-407E-B1DB-23A301DB5580} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E16E8A02-5F7D-407E-B1DB-23A301DB5580} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully</p><p>HKEY_CLASSES_ROOT\CLSID\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully</p><p>HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully</p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully</p><p></p><p>==== Deleting CLSID Registry Values ======================</p><p></p><p></p><p>==== Reset IE Proxy ======================</p><p></p><p>Value(s) before fix:</p><p>"ProxyServer"="http=127.0.0.1:49187;https=127.0.0.1:49187"</p><p>"ProxyOverride"="<-loopback>"</p><p>"ProxyEnable"=dword:00000000</p><p></p><p>Value(s) after fix:</p><p>"ProxyEnable"=dword:00000000</p><p></p><p>==== Deleting Registry Keys ======================</p><p></p><p>HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{64A4ABCA-CF3D-C548-2DC4-72A55DC5882A} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D8A9D3D9-F414-952D-AC93-E5F96D47B5BD} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F6A71DC7-28F4-C6C7-8FA9-8A56C80FC96A} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BrowserSafeguard deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\S-576482620 deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{4d349a54} deleted successfully</p><p>HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{be0fb33b} deleted successfully</p><p></p><p>==== Empty IE Cache ======================</p><p></p><p>C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Users\Owner\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully</p><p>C:\Users\Owner\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully</p><p>C:\Users\Owner\Desktop\Geek Squad Back up\Users\Dawn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Users\Owner\Desktop\Geek Squad Back up\Users\Dawn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully</p><p>C:\Users\Owner\Desktop\Geek Squad Back up\Users\Dawn\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Users\Owner\Desktop\Geek Squad Back up\Users\Dawn\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Users\Owner\Desktop\Geek Squad Back up\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\Users\Owner\Desktop\Geek Squad Back up\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully</p><p>C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully</p><p>C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully</p><p>C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully</p><p>C:\Users\Owner\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully</p><p>C:\Users\Owner\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully</p><p>C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully</p><p>C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully</p><p></p><p>==== Empty FireFox Cache ======================</p><p></p><p>No FireFox Profiles found</p><p></p><p>==== Empty Chrome Cache ======================</p><p></p><p>C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully</p><p></p><p>==== Empty All Flash Cache ======================</p><p></p><p>Flash Cache Emptied Successfully</p><p></p><p>==== Empty All Java Cache ======================</p><p></p><p>Java Cache cleared successfully</p><p></p><p>==== C:\zoek_backup content ======================</p><p></p><p>C:\zoek_backup (files=209 folders=77 1533522807 bytes)</p><p></p><p>==== Empty Temp Folders ======================</p><p></p><p>C:\Users\Default\AppData\Local\Temp emptied successfully</p><p>C:\Users\Default User\AppData\Local\Temp emptied successfully</p><p>C:\Users\Owner\AppData\Local\Temp will be emptied at reboot</p><p>C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully</p><p>C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully</p><p>C:\WINDOWS\Temp will be emptied at reboot</p><p></p><p>==== After Reboot ======================</p><p></p><p>==== Empty Temp Folders ======================</p><p></p><p>C:\WINDOWS\Temp successfully emptied</p><p>C:\Users\Owner\AppData\Local\Temp successfully emptied</p><p></p><p>==== Empty Recycle Bin ======================</p><p></p><p>C:\$RECYCLE.BIN successfully emptied</p><p></p><p>==== Deleting Files / Folders ======================</p><p></p><p>"C:\PROGRA~3\Trusted Publisher" not found</p><p></p><p>==== EOF on Sat 11/08/2014 at 13:58:32.22 ======================</p></blockquote><p></p>
[QUOTE="DawnMohrbacher, post: 295136, member: 30421"] Any help would of course be so appreciated. Then I will follow your directions on protecting the computer more carefully! Zoek.exe v5.0.0.0 Updated 06-November-2014 Tool run by Owner on Sat 11/08/2014 at 13:41:40.21. Microsoft Windows 8.1 6.3.9600 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Owner\Downloads\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 11/8/2014 1:44:34 PM Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Batch Command(s) Run By Tool====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~2\YoouuttubbeAdBlocke deleted C:\ProgramData\YoouuttubbeAdBlocke deleted C:\ProgramData\GoSSave deleted C:\PROGRA~2\PrriceoCihhoP deleted C:\ProgramData\PrriceoCihhoP deleted C:\ProgramData\BestSaveForYou deleted C:\Users\Owner\AppData\LocalLow\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted C:\Users\Owner\AppData\LocalLow\{44925416-93EF-F42F-5775-D62213216CAF} deleted C:\Users\Owner\AppData\LocalLow\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted C:\Users\Owner\AppData\Local\Packages\windows_ie_ac_001\AC\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted C:\Users\Owner\AppData\Local\Packages\windows_ie_ac_001\AC\{44925416-93EF-F42F-5775-D62213216CAF} deleted C:\Users\Owner\AppData\Local\Packages\windows_ie_ac_001\AC\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted C:\PROGRA~3\29becdccc39fb05b deleted C:\PROGRA~3\JoniiiCoupOn deleted C:\PROGRA~3\NaEWSaver deleted C:\PROGRA~3\SaveClicker deleted C:\PROGRA~2\SaveClicker deleted C:\PROGRA~2\Supporter deleted C:\PROGRA~2\Browsersafeguard deleted C:\PROGRA~2\SearchProtect deleted C:\PROGRA~2\Yahoo! deleted C:\PROGRA~2\Consumer Input deleted C:\PROGRA~2\GS_Booster deleted C:\Users\Owner\AppData\Roaming\GetRightToGo deleted C:\PROGRA~3\Yahoo! deleted C:\PROGRA~3\PriceCHop deleted C:\PROGRA~3\PC Optimizer Pro deleted C:\Users\Owner\AppData\Local\SearchProtect deleted C:\Users\Owner\AppData\Local\visi_coupon deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\Users\Owner\AppData\LocalLow\YahooCouponAddOn deleted C:\windows\SysNative\tasks\ConsumerInputUpdateTaskMachineCore deleted C:\windows\SysNative\tasks\ConsumerInputUpdateTaskMachineUA deleted C:\WINDOWS\tasks\ConsumerInputUpdateTaskMachineCore.job deleted C:\WINDOWS\tasks\ConsumerInputUpdateTaskMachineUA.job deleted C:\windows\SysNative\Tasks\BrowserSafeguard Update Task deleted C:\WINDOWS\tasks\GS_Booster-S-576482620.job deleted C:\windows\SysNative\tasks\GS_Booster-S-576482620 deleted C:\WINDOWS\SysNative\config\systemprofile\Searches deleted C:\windows\SysNative\GroupPolicy\Machine deleted C:\windows\SysNative\GroupPolicy\User deleted C:\windows\SysNative\GroupPolicy\GPT.INI deleted C:\WINDOWS\Syswow64\GroupPolicy\gpt.ini deleted "C:\PROGRA~3\Trusted Publisher\GS_Booster\GS_Booster.exe" deleted "C:\PROGRA~3\Trusted Publisher" not deleted "C:\PROGRA~3\Trusted Publisher\GS_Booster" not deleted ==== Fake Chromium Profiles Check ====================== Fake profile C:\Users\Administrator\AppData\Local\Torch deleted Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome deleted Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome SxS deleted Fake profile C:\Users\Administrator\AppData\Local\Comodo\Dragon deleted Fake profile C:\Users\Administrator\AppData\Local\Chromatic Browser deleted Fake profile C:\Users\Guest\AppData\Local\Torch deleted Fake profile C:\Users\Guest\AppData\Local\Google\Chrome deleted Fake profile C:\Users\Guest\AppData\Local\Google\Chrome SxS deleted Fake profile C:\Users\Guest\AppData\Local\Comodo\Dragon deleted Fake profile C:\Users\Guest\AppData\Local\Chromatic Browser deleted Fake profile C:\Users\HomeGroupUser$\AppData\Local\Torch deleted Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome deleted Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS deleted Fake profile C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon deleted Fake profile C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser deleted Fake profile C:\Users\Owner\AppData\Local\Torch deleted Fake profile C:\Users\Owner\AppData\Local\Google\Chrome SxS deleted Fake profile C:\Users\Owner\AppData\Local\Comodo\Dragon deleted Fake profile C:\Users\Owner\AppData\Local\Chromatic Browser deleted ==== Chromium Look ====================== Google Voice Search Hotword (Beta) - Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn PriceCHop - Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\bonfmkhdhmcnfkhhjjdjgnnekiafklhk ==== Chromium Fix ====================== C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_[url="http://www.superfish.com_0.localstorage"]www.superfish.com_0.localstorage[/url] deleted successfully C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_[url="http://www.superfish.com_0.localstorage-journal"]www.superfish.com_0.localstorage-journal[/url] deleted successfully C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_[url="http://www.superfish.com_0.localstorage"]www.superfish.com_0.localstorage[/url] deleted successfully C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_[url="http://www.superfish.com_0.localstorage-journal"]www.superfish.com_0.localstorage-journal[/url] deleted successfully C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\bonfmkhdhmcnfkhhjjdjgnnekiafklhk deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="[url]http://www.google.com/[/url]" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="[url]http://websearch.calcitapp.info/[/url]" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Start Page"="[url]http://websearch.calcitapp.info/[/url]" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="[url]http://www.google.com/[/url]" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="[url]http://go.microsoft.com/fwlink/?LinkId=69157[/url]" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Start Page"="[url]http://go.microsoft.com/fwlink/?LinkId=69157[/url]" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" {012E1000-F331-11DB-8314-0800200C9A66} Google Url="[url]http://www.google.com/search?q={searchTerms}[/url]" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="[url]http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02[/url]" {06C03F00-CA98-417A-B361-24876253224C} Unknown Url="Not_Found" {2fa28606-de77-4029-af96-b231e3b8f827} Unknown Url="Not_Found" {b7fca997-d0fb-4fe0-8afd-255e89cf9671} Unknown Url="Not_Found" {D944BB61-2E34-4DBF-A683-47E505C587DC} eBay Url="[url]http://rover.ebay.com/rover/1/711-154371-11896-2/4[/url]" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E16E8A02-5F7D-407E-B1DB-23A301DB5580} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E16E8A02-5F7D-407E-B1DB-23A301DB5580} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Internet Explorer\SearchScopes\{06C03F00-CA98-417A-B361-24876253224C} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} deleted successfully HKEY_USERS\S-1-5-21-3575586604-2702209178-3045525582-1001\Software\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully HKEY_CLASSES_ROOT\CLSID\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{21C344D6-6E0A-AA63-146F-81088FE5C4C5} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully HKEY_CLASSES_ROOT\CLSID\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44925416-93EF-F42F-5775-D62213216CAF} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully HKEY_CLASSES_ROOT\CLSID\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{658a8288-d644-4721-b4e2-0baea80af910} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully HKEY_CLASSES_ROOT\CLSID\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c729d6de-20c7-4e5c-a612-dbde1def4da3} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully HKEY_CLASSES_ROOT\CLSID\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cf4fbe64-f07d-4242-becf-8ea5427de7aa} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully HKEY_CLASSES_ROOT\CLSID\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d6ca7154-7149-4d71-adae-ef6da11c0466} deleted successfully HKEY_CLASSES_ROOT\CLSID\{E16E8A02-5F7D-407E-B1DB-23A301DB5580} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{E16E8A02-5F7D-407E-B1DB-23A301DB5580} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E16E8A02-5F7D-407E-B1DB-23A301DB5580} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E16E8A02-5F7D-407E-B1DB-23A301DB5580} deleted successfully HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully HKEY_CLASSES_ROOT\CLSID\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ED457D3D-19E6-D519-1E8E-E9DA7226E3A1} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Reset IE Proxy ====================== Value(s) before fix: "ProxyServer"="http=127.0.0.1:49187;https=127.0.0.1:49187" "ProxyOverride"="<-loopback>" "ProxyEnable"=dword:00000000 Value(s) after fix: "ProxyEnable"=dword:00000000 ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{64A4ABCA-CF3D-C548-2DC4-72A55DC5882A} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D8A9D3D9-F414-952D-AC93-E5F96D47B5BD} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F6A71DC7-28F4-C6C7-8FA9-8A56C80FC96A} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\BrowserSafeguard deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\S-576482620 deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{4d349a54} deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{be0fb33b} deleted successfully ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Owner\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Owner\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\Users\Owner\Desktop\Geek Squad Back up\Users\Dawn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Owner\Desktop\Geek Squad Back up\Users\Dawn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Owner\Desktop\Geek Squad Back up\Users\Dawn\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Owner\Desktop\Geek Squad Back up\Users\Dawn\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Owner\Desktop\Geek Squad Back up\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Owner\Desktop\Geek Squad Back up\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Owner\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Owner\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=209 folders=77 1533522807 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Owner\AppData\Local\Temp will be emptied at reboot C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\Owner\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\PROGRA~3\Trusted Publisher" not found ==== EOF on Sat 11/08/2014 at 13:58:32.22 ====================== [/QUOTE]
Insert quotes…
Verification
Post reply
Top